Course · Training · Workshop

Container & Kubernetes Security

Intensive Introduction to Security Aspects of Kubernetes and Container Environments, including Best Practices and Overview of Potential Threats.

In this course, participants will learn the fundamentals of security in Kubernetes and Container environments, and how to protect their applications and infrastructures from potential threats.

What participants say

Outstanding course for starting the K8s and container security learning journey.
Christian Christian
Site Reliability Engineer, CSS

These customers booked courses in the same topic cluster.More customers →

Content

The course guides participants through the following topics. Depending on the questions and interests of the participants, focus areas will be emphasized and ad-hoc topics added:

– Introduction to Container and Kubernetes Security:

  • Security challenges and strategies
  • Overview of security architecture and tools – Container Image Security:
  • Secure Base Images and Image Scanning
  • Integrity and Trustworthiness of Images
  • Minimization of Image Size and Attack Surface
  • Hardening Container Images – Network Security in Kubernetes:
  • Isolation of Namespaces and Network Resources
  • Network Policies and Ingress/Egress Rules
  • Brief Overview of Service Mesh and mTLS (with Cilium)
  • Security Considerations for Ingress
  • Introduction to Gateway API – Kubernetes API and Authentication:
  • RBAC (Role-Based Access Control)
  • API Security and Auditing
  • Secrets Management and Encryption – Pod Security and Resource Limitations:
  • Pod Security Admission Controller
  • Container Runtime Security
  • Resource Quotas and LimitRanges
  • Security Mechanisms with gVisor – Monitoring and Logging for Security Incidents:
  • Overview of Tools and Techniques
  • Monitoring with Falco – Automation of Security Checks in CI/CD Pipelines:
  • Integrating Security Checks into Development Cycle
  • Using Tools like Trivy and kube-bench
  • Signing and Verifying Container Images with Sigstore Cosign – Policy Enforcement:
  • Using Gatekeeper/OPA and Kyverno for Policy Enforcement – Mini “Capture The Flag” Example:
  • Hands-on exercises to reinforce security knowledge

You will not only get to know these concepts, but also implement them in practice.

The actual course content may differ from the above depending on the trainer, delivery, duration and the composition of participants.

Request this course in-house

By submitting you accept our Privacy Policy.

Request a public date

No suitable public date? Register without obligation — once there is enough interest we schedule a new public date and let you know first.

Number of participants (approx.)

More than 3 participants? Best to request a dedicated in-house date directly.

By submitting you accept our Privacy Policy.

More about Kubernetes Security

Kubernetes Security is a multi-layered approach to protecting container workloads and cluster infrastructure. It encompasses aspects such as authentication, authorization, network security, pod security, and supply chain security, which together form a comprehensive security model.

Further resources:

History

The development of Kubernetes security began with fundamental concepts like RBAC, developed by Eric Tune and Jordan Liggitt. As Kubernetes adoption in production environments grew, security became a major focus of the community.

A significant milestone was the introduction of Pod Security Policies (PSP) in 2016, later replaced by the Pod Security Admission Controller. Tim Allclair and the Kubernetes Security Team led this evolution. The integration of Gatekeeper as a policy engine marked another important step.

Today, Kubernetes security is its own ecosystem with tools like Falco (developed by Sysdig), Trivy (by Aqua Security), and Sigstore for supply chain security. The establishment of the Security Special Interest Group (SIG) and the introduction of the CKS certification demonstrate the growing importance of security in the Kubernetes world. Projects like the Gateway API and service mesh technologies continue to expand security capabilities.