
Kubernetes Security tools(DevSecOps keynote) | cloud native security | Falco | Kubescape | Terrascan
Source: YouTube · Kubesimplify · published Jan 9, 2022 · 31:53
This presentation introduces DevSecOps in cloud-native environments, emphasizing security integration at every layer of the development lifecycle 1:06-2:25. The speaker explains how security has evolved with microservices and containerization, requiring a "shift left" approach where security is embedded throughout the DevOps pipeline rather than being a final bottleneck.
Key Takeaways:
• DevSecOps integrates security into the entire development pipeline, moving from traditional DevOps to include security checks at each stage to protect customer data and prevent vulnerabilities 1:06-2:25
• The "4 Cs of Security" framework (Cloud, Cluster, Containers, Code) highlights how each layer in cloud-native ecosystems requires security scanning due to increased attack surfaces 5:55-7:13
• Falco, a CNCF incubating project, provides runtime security by monitoring system calls through kernel modules and eBPF probes, comparing them against security rules 11:14-12:14
• Terrascan scans infrastructure as code for compliance and security violations before provisioning, supporting Terraform, Docker files, and Kubernetes configurations 14:32-15:45
• Kubescape ensures Kubernetes security from development to production, integrating with CI/CD systems and providing scanning against frameworks like NSA, MITRE, and Armor 17:07-18:24
The demo showcases both Terrascan and Kubescape in action, scanning Docker files and Kubernetes clusters to identify security issues like missing resource limits, privilege escalations, and RBAC misconfigurations 23:36-29:48.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
so hello to everyone so this devsecops conference and this is the the first session to i'll so i'll be kind of setting the context overall we'll be discussing a few of the tools and there'll be like hands-on demo as well so i'm really excited for this i hope you are too so before getting started uh a bit about myself i'm director of technical evangelism working at sibo uh cbo is a company uh that builds uh managed community service based on k3s uh and some of the other compute and other stuff which is coming up so you can check that out i'm a cncf ambassador i'm uh all the kubernetes certified uh except for kcnn because i'm one of the smes over there you can follow me on twitter i'm very active over there tweeting out the latest of the greatest in tech same with the youtube channel you can…