Главная
Study mode:
on
1
Intro
2
Background: K8s Secrets
3
Motivation: K8s Secrets Protection
4
Confidential Computing
5
TEE-based KMS Plugin
6
TEE-based KMS Provider
7
TEE-based Kubectl
8
TEE-based Secrets Protection (cont.)
9
KMS Plugin (cont.)
10
KMS Plugin as a Service
11
One binary: TEE Transparency
12
Occlum: SGX Dev Made Easy
13
Occlum: Major Features
14
Occlum: Container-Inspired Interface
15
Demo
16
Summary & Next Steps
Description:
Explore an innovative approach to enhancing Kubernetes secrets protection in this conference talk. Learn about the implementation of Trusted Execution Environment (TEE) and enhanced authentication to create an end-to-end secret hardening solution for Kubernetes clusters. Discover how to guard secrets while in use, at rest, and in transit by making changes to kubectl, Kubernetes master, and node components. Gain insights into TEE transparency for developers and users, and witness a practical demonstration. Understand the real-world application of this technology at Alibaba and learn about the proposed Kubernetes Enhancement Proposal (KEP) for the community. Delve into topics such as confidential computing, TEE-based KMS plugins and providers, and the Occlum framework for simplified SGX development.

Putting an Invisible Shield on Kubernetes Secrets

CNCF [Cloud Native Computing Foundation]
Add to list