Container security: Do containers actually contain? Should you care? - 2015 Red Hat Summit

  Рет қаралды 9,481

Red Hat Summit

Red Hat Summit

Күн бұрын

Пікірлер: 14
@rhc287
@rhc287 6 жыл бұрын
Great talk.
@dejagerlaubscher5127
@dejagerlaubscher5127 8 жыл бұрын
this is awesome training !
@unixbhaskar
@unixbhaskar 9 жыл бұрын
Cool Dan! love your work and talk...way to go...cheers mate.
@johnschiwitz4412
@johnschiwitz4412 8 жыл бұрын
I enjoyed your systemd talk last June. I noticed you went to Holy Cross and WPI I worked at Holy Cross and lived on Salisbury Street about a mile from WPI. We are implementing containers here at Honda, thanks again for clearing up these topics
@geraldjustice1009
@geraldjustice1009 8 жыл бұрын
Sadly the camera focussed too often on the speaker and some slides were not shown or were shown far too quickly.
9 жыл бұрын
Do *you* have pigs in a park?
@tomascrhonek
@tomascrhonek 9 жыл бұрын
Video jsem neviděl, ale když jsem četl u nspawnu, že securita ještě není moc doladěná, tak jsem si myslel, že je to takové to klasické co se týká všech kontejnerů. No a v stačilo si dát v nspawnu cat /proc/mounts a bylo celkem jasné, jak moc je ta bezpečnost nedoladěná. Tím nehodnotím, jestli je to dobře nebo špatně, ale člověk by měl znát co všechno to propustí dovnitř kontejneru.
9 жыл бұрын
Nspawn byl vytvořen pro testovani systemd. Do budoucna by se ale mohl pouzivat do produkce. Ambice takove nemel, ale vypada to, ze se uchyti.
@tomascrhonek
@tomascrhonek 9 жыл бұрын
To je možné, já jej používám na testování aplikací, které vyžadují nějaké jiné nastavení systému než má aktuálně hostitel. Po testování následuje btrfs sub del. Na bezpečnostní oddělení bych asi žádný kontejner nepoužil.
@VasuThiyagarajan
@VasuThiyagarajan 9 жыл бұрын
Containers don't contain...but if you get it from RHEL it does...seriously ?
@TerryBowling
@TerryBowling 9 жыл бұрын
+Vasu Thiyagarajan That is not what he is saying at all. I think you need to listen more carefully. He is saying that it is naive to think that containers truly contain all by themselves. SELinux improves security significantly and Red Hat is working with the community to add things like SECCOMP and User Name Spaces to improve this further. So if you're blindly using containers thinking it's secure, you're wrong. If you're using the Red Hat ecosystem, Red Hat is helping you to fill the gaps. Not saying you can't do it with other platforms, but there is a lot to know and Red Hat has the most engineers and security resources to ensure the gaps are identified and filled. And we submit for the government security certifications (CC, FIPS, etc) so there are additional audits and eyeballs critiquing the platform.
@VasuThiyagarajan
@VasuThiyagarajan 9 жыл бұрын
Thanks for clarification
@zofe
@zofe 3 жыл бұрын
Backward-compatibility is backward socioeconomic mentality of tuning and patching, rather not R&D thus replacing engineers with copycats - who exponentiate compexity. Jim Keller, a prominent CPU design-leader, states that a 5-years cycle of redesign from scratch makes sense for CPUs ... so what about OS fundamentals, then? kzbin.info/www/bejne/hJOVpZiYjqaUhaM
@kadiatoutraore9538
@kadiatoutraore9538 8 жыл бұрын
awa fjg
Security-enhanced Linux for mere mortals - 2015 Red Hat Summit
52:18
Red Hat Summit
Рет қаралды 65 М.
번쩍번쩍 거리는 입
0:32
승비니 Seungbini
Рет қаралды 182 МЛН
"Идеальное" преступление
0:39
Кик Брейнс
Рет қаралды 1,4 МЛН
Почему Катар богатый? #shorts
0:45
Послезавтра
Рет қаралды 2 МЛН
I'VE MADE A CUTE FLYING LOLLIPOP FOR MY KID #SHORTS
0:48
A Plus School
Рет қаралды 20 МЛН
Red Hat CEO Jim Whitehurst opens 2015 Summit
42:12
Red Hat Summit
Рет қаралды 19 М.
SEVEN things about API security - Philippe De Ryck - NDC Oslo 2024
55:36
Are you listening to what SELinux is telling you?
1:03:14
Red Hat Summit
Рет қаралды 14 М.
Run containers on bare metal already!
41:12
Bryan Cantrill
Рет қаралды 38 М.
Thursday morning general session - May 9 - Red Hat Summit 2019
2:14:00
Red Hat Summit
Рет қаралды 12 М.
Demystifying systemd
44:59
Red Hat Summit
Рет қаралды 24 М.
Burr Sutter & company blow your mind at Red Hat Summit 2016
41:12
Red Hat Summit
Рет қаралды 13 М.
2012 Red Hat Summit: SELinux For Mere Mortals
52:10
Red Hat
Рет қаралды 102 М.
번쩍번쩍 거리는 입
0:32
승비니 Seungbini
Рет қаралды 182 МЛН