Putting an Invisible Shield on Kubernetes Secretsin the clear in memory ü leak ALL DEKs ü leak ALL secrets ü trust collapse! • DEK decryption interfaces invoked by fake users Motivation: K8s Secrets Protection • Kube-on-Kube [1] ü Components => Host (KMS provider) compromise Ø leak DEKs Ø leak Secrets • Fraudsters calling DEK decryption interfaces TEE-based Kubectl • Address security threats • Client compromise Ø kubeconfig maliciously reused SGX servers deployed w/ sgx-device- plugin daemonset [1] • kms-plugins deployed as deployment • Interfaces • https + connection reuse • certificate: similar to apiserver ó etcd (X.509) • Version-based0 码力 | 33 页 | 20.81 MB | 1 年前3
QCon北京2018/QCon北京2018-《Kubernetes-+面向未来的开发和部署》-Michael+ChenCreates virtual IP for external access • Interfaces with local iptables • Load-balance interface for Pods • Creates virtual IP for external access • Interfaces with local iptables The Kubernetes Runtime Containers Kubernetes: Manage Container workload, Desired State Management, Decouple Service Interfaces & Backedn Workload PKS: Manage Kubernetes Lifecycle & Underline Infrastructure Summary Modern0 码力 | 42 页 | 10.97 MB | 1 年前3
多租户Kubernetes VM Solutions for Multi-Tenant ApplicationsService Account virtlet solution Virtlet Pros define VM as Pod supports using multiple interfaces SR-IOV NFV Environments Virtlet Cons limited storage options more configurations VM actions0 码力 | 33 页 | 3.34 MB | 1 年前3
k8s操作手册 2.3show #查看网桥(虚拟交换机) bridge name bridge id STP enabled interfaces cni0 8000.9e3551d62fed no veth57d7a776 docker0 8000.0242f0503f0d0 码力 | 126 页 | 4.33 MB | 1 年前3
共 4 条
- 1













