Kubernetes Security Fundamentals (LFS460)
Use hands-on labs to learn new skills and knowledge across a range of security best practices for container-based applications & Kubernetes platforms that will make your IT career profile stand out.
Description
Use hands-on labs to learn new skills and knowledge across a range of security best practices for container-based applications & Kubernetes platforms that will make your IT career profile stand out. In this course you learn to maintain security in dynamic, multi-project environments & address security concerns for cloud production environments.
Summary
Use hands-on labs to learn new skills and knowledge across a range of security best practices for container-based applications & Kubernetes platforms that will make your IT career profile stand out.
What You'll Learn
- This course exposes you to knowledge and skills needed to maintain security in dynamic, multi-project environments.
- This course addresses security concerns for cloud production environments and covers topics related to the security container supply chain, discussing topics from before a cluster has been configured through deployment, and ongoing, as well as agile use, including where to find ongoing security and vulnerability information.
- The course includes hands-on labs to build and secure a Kubernetes cluster, as well as monitor and log security events.
Prerequisites
- A good understanding of Linux
- Familiarity with the command line
- Familiarity with package managers
- Familiarity with Git and GitHub
- Proficiency working with Kubernetes (the equivalent of being CKA-certified)
Outline
- The Linux Foundation®
- The Linux Foundation® Training
- The Linux Foundation® Certifications
- The Linux Foundation® Digital Badges
- Laboratory Exercises, Solutions and Resources
- Things Change in Linux and Open Source Projects
- Platform Details
- Multiple Projects
- What is Security?
- Assessment
- Prevention
- Detection
- Reaction
- Classes of Attackers
- Types of Attacks
- Attack Surfaces
- Hardware and Firmware Considerations
- Security Agencies
- Manage External Access
- Labs
- Image Supply Chain
- Runtime Sandbox
- Verify Platform Binaries
- Minimize Access to GUI
- Policy Based Control
- Labs
- Update Kubernetes
- Tools to Harden the Kernel
- Kernel Hardening Examples
- Mitigating Kernel Vulnerabilities
- Labs
- Restrict Access to API
- Enable Kube-apiserver Auditing
- Configuring RBAC
- Pod Security Admission
- Minimize IAM Roles
- Protecting etcd
- CIS Benchmark
- Using Service Accounts
- Labs
- Firewalling Basics
- Network Plugins
- Mitigate Brute Force Login Attempts
- Ingress Objects
- Pod to Pod Encryption
- Restrict Cluster Level Access
- Labs
- Minimize Base Image
- Static Analysis of Workloads
- Runtime Analysis of Workloads
- Overview of SBOM
- Container Immutability
- Mandatory Access Control
- SELinux
- AppArmor
- Generate AppArmor Profiles
- Labs
- Understanding Phases of Attack
- Preparation
- Understanding an Attack Progression
- During an Incident
- Handling Incident Aftermath
- Intrusion Detection Systems
- Threat Detection
- Behavioral Analytics
- Labs