Evolution of Kubernetes Security | KubeCon EU 2023

Evolution of Kubernetes Security | KubeCon EU 2023

Cloud Security Podcast - we are continuing with our "Kubernetes Security & KubeCon EU 2023" and for the final episode in this series Kubernetes Security Panel from KubeCon EU 2023. Kubernetes Security has evolved since it's inception with many defaults being more secure and some still insecure or has it not evolved at all. Andrew Martin (Control Plane), Matt Jarvis (Snyk), Kerim Satirli (Hashicorp) were on the Kubernetes Security Panel organized by Cloud Security Podcast.


Episode ShowNotes, Links and Transcript on Cloud Security Podcast: ⁠⁠⁠⁠⁠⁠⁠⁠www.cloudsecuritypodcast.tv⁠⁠⁠⁠⁠⁠⁠⁠


FREE CLOUD BOOTCAMPs on ⁠⁠⁠⁠⁠⁠⁠⁠www.cloudsecuritybootcamp.com⁠⁠⁠⁠⁠⁠⁠⁠


Host Twitter: Ashish Rajan (⁠⁠⁠⁠⁠⁠⁠⁠@hashishrajan⁠⁠⁠⁠⁠⁠⁠⁠)

Guest Socials: Andrew Martin (Control Plane), Matt Jarvis (Snyk), Kerim Satirli (Hashicorp)

Podcast Twitter - ⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecPod⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠@CloudSecureNews⁠⁠⁠⁠⁠⁠⁠⁠


If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:

- ⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security News ⁠⁠⁠⁠⁠⁠⁠⁠

- ⁠⁠⁠⁠⁠⁠⁠⁠Cloud Security BootCamp⁠⁠⁠⁠⁠⁠⁠⁠


Spotify TimeStamp for Interview Questions

(00:00) Introduction

(04:28) A bit about Kerim, Andy and Matt

(05:13) What is Kubernetes?

(06:49) How do you describe Cloud Native Security?

(10:21) How Kubecon and Kubernetes has changed over the years?

(15:56) The growing presence of security in Kubecon

(22:10) Cloud Security and Cloud Native Security

(23:00) Maintenance of Kubernetes

(24:17) Shared Responsibility Model

(27:37) Single Cluster vs Multi Cluster

(34:34) Failure of Workload Identity

(36:11) Recommendations for learning

(42:06) Disaster Recovery for Kubernetes

(47:51) ChatGPT - Problem, Solution or Fad?


See you at the next episode!

Jaksot(344)

Secret Management for Modern Apps Explained

Secret Management for Modern Apps Explained

In this episode of the Virtual Coffee with Ashish edition, we spoke with Dylan Ayrey (@insecurenature) is a Professional Hacker and Co-Founder of Truffle Security (@trufflesec) Episode ShowNotes, Link...

16 Tammi 202248min

CISO in a Cloud World in 2022 - Stu Hirst

CISO in a Cloud World in 2022 - Stu Hirst

In this episode of the Virtual Coffee with Ashish edition, we spoke with Stu Hirst (Linkedin-Stu Hirst) is the Chief Information Security Officer (CISO) of Trustpilot (@Trustpilot). Episode ShowNotes,...

12 Tammi 202239min

UK Financial Regulators monitoring Cloud Providers Closely

UK Financial Regulators monitoring Cloud Providers Closely

Cloud Security News this week 12 Jan 2022 UK’s financial regulators - The Prudential Regulation Authority is looking to increase it’s monitoring of Cloud providers like AWS, Azure and Google Cloud. ...

12 Tammi 20224min

Building Modern Identity (IAM) Roadmap for Cloud

Building Modern Identity (IAM) Roadmap for Cloud

In this episode of the Virtual Coffee with Ashish edition, we spoke with Fred Wilmot (@fewdisc) is an ex-Veteran and Chief Information Security Officer (CISO) of JumpCloud (@JumpCloud). Episode ShowNo...

9 Tammi 202248min

Google invests in Security + Microsoft's Log4Shell Update

Google invests in Security + Microsoft's Log4Shell Update

Cloud Security News this week 5 Jan 2022 Google has acquired security orchestration, automation and response (SOAR) provider, Siemplify. Neither company has disclosed any amounts however sources in...

5 Tammi 20225min

Building Scalable Authorization in Cloud Native Apps

Building Scalable Authorization in Cloud Native Apps

In this episode of the Virtual Coffee with Ashish edition, we spoke with Or Weis (@OrWeis) co-founder and CEO of Permit.io (@permit_io). Episode ShowNotes, Links and Transcript on Cloud Security Podca...

2 Tammi 202250min

The Latest with Log4J

The Latest with Log4J

Cloud Security News this week 22 December 2021 Most folks in cybersecurity have been consumed with all things Log4shell with a CVSS score of 10, since last week. Check out last week’s episode or our...

22 Joulu 20213min

Log4j - How the Cloud Providers responded!

Log4j - How the Cloud Providers responded!

Cloud Security News this week 15 December 2021 This week, the world of cybersecurity has been consumed by the Log4Shell vulnerability. So whats it all about. Log4j is a Java library for logging er...

15 Joulu 20212min