Главная
Study mode:
on
1
Run As “Root”, Not Root: User Namespaces In K8s- Marga Manterola, Isovalent & Rodrigo Campos Catelin
Description:
Explore user namespaces in Kubernetes through this informative conference talk. Discover how a simple boolean setting in pod YAML can mitigate numerous high and critical CVEs. Learn about the kernel feature that isolates container users from host users, significantly enhancing security by reducing privileges if a process escapes the container. Understand the implementation, current state of the KEP, and future challenges in this area. Gain insights on enabling user namespaces in your cluster to improve security for container workloads running as root without additional changes.

User Namespaces in Kubernetes: Running as "Root" Without Root Privileges

CNCF [Cloud Native Computing Foundation]
Add to list
0:00 / 0:00