秘钥管理秘钥Turtles all the way down - Securely managing Kubernetes Secretssecrets? ● Attractive target ○ Controls access or use of sensitive resources ● Common attack vector ○ Checked into Github ○ Accessible by users who shouldn’t have access, e.g., CEO ○ Stored in public storage key is compromised ○ Time available for attempts to penetrate physical, procedural, and logical access ○ Time available for computationally intensive cryptanalytic attacks ● A cryptoperiod is the time practices Managing DEKs: ● Generate DEKs locally ● Use a strong cryptographic algorithm ● For easy access, store the DEK near the data that it encrypts ● Ensure DEKs are encrypted at rest ● Don’t use0 码力 | 52 页 | 2.84 MB | 1 年前3
QCon北京2018/QCon北京2018-《Kubernetes-+面向未来的开发和部署》-Michael+Chenfor Pods • Creates virtual IP for external access • Interfaces with local iptables • Load-balance interface for Pods • Creates virtual IP for external access • Interfaces with local iptables The Kubernetes organize items in a cluster Labels, Annotations & Selectors Tags for component grouping and methods to access them Service Discovery An object associated to a label selector to provide a LB and Service DNS0 码力 | 42 页 | 10.97 MB | 1 年前3
Kubernetes安全求生指南Security Best Practices ©2019 VMware, Inc. 7 關閉公開存取 (Disable public access) 實施角色型存取權控管 (Implement role-based access control) 將 Kubernetes密鑰加密 (Encrypt secrets at rest) 設置 Kubernetes 的許可控制器 Ci/CD Application DevOPS Owner Consumes PKS API/CLI Day 1 & Day 2 for k8s clusters Manages access to k8s API for developers IT Operator IaaS Management Internet User Application User Trust0 码力 | 23 页 | 2.14 MB | 1 年前3
Apache OpenWhisk + Kubernetes:
A Perfect Match for Your Serverless PlatformKuberentes Servcie is an abstraction which defines a logical set of Pods and a policy by which to access them. • Service provides a way for applications to communicate with each other on K8s platform objects used in OW charts • ConfigMap: like nginx deployment configuration • Secrets: like DB access credentials • Ingress Component Launch Sequence • In Kubernetes, we can use the following0 码力 | 24 页 | 3.53 MB | 1 年前3
绕过conntrack,使用eBPF增强 IPVS优化K8s网络性能VIP using a load balancer • Two types • ClusterIP provides in-cluster access • NodePort provides out-of-cluster access • Major modes • Iptables • IPVS Iptables mode • How it works • DNAT at0 码力 | 24 页 | 1.90 MB | 1 年前3
多雲一體就是現在:
GOOGLE CLOUD 的
KUBERNETES
混合雲戰略upgrade path to the latest Kubernetes releases that have been validated and tested by Google ● Access to Container services on GCP such as Cloud Build, Container Registry, Audit Logging, and more. Orchestrate and manage on-prem containers just like GKE in the cloud Consistent operating model with access to GCP services across hybrid environments Single-pane-of-glass for multiple Kubernetes clusters0 码力 | 32 页 | 2.77 MB | 1 年前3
Amazon Elastic Kubernetes Service (EKS) 初探秘log-leaking} • sensitive config (passwords, API keys, etc.) • gotchas: commits-to-source, non-separated access (dev has cleartext password) { • business core data • Personal Identifiable Information (PII) Web Services, Inc. or its Affiliates. All rights reserved. Amazon Confidential AWS Identity and Access Management (IAM) 身份验证 Kubectl 3) Authorizes AWS identity with RBAC K8s API 1) Passes AWS identity0 码力 | 39 页 | 1.83 MB | 1 年前3
基于Kubernetes构建容器云平台的实践
- UCloud优刻得实验室负责⼈ 叶理灯10.9.1.4 vswitch VPC Subnet 10.9.0.1/16 Think in Cloud . 北北京 UK8S管理理服务架构 ⽇日志 监控 告警 API Access Dashboard Terminal Job Watcher Operator MongoDB Redis Watcher1 Wathcer2 WatcherN Cluster1 KUN-apiserver pod1 podN redis-svc pod1 podN watcher- operator-svc job1 jobN watcher1 watcherN access-svc Think in Cloud . 北北京 UK8S管理理服务特点 A. 完全的容器器化和微服务化。 B. 所有管理理服务全部运⾏行行在k8s上。 C. 基于k8s的api0 码力 | 30 页 | 3.52 MB | 1 年前3
Kubernetes开源书 - 周立bernetes-dashboard:/proxy/#!/overview? namespace=default 参考: https://kubernetes.io/docs/tasks/access-application-cluster/web-ui-dashboard/ 02-安装单机版Kubernetes 9 使⽤Kubespray部署⽣产可⽤的Kubernetes集群 (1.11 Controller:填充Endpoint对象(即:连接Service&Pod)。 Service Account & Token Controllers:为新的namespace创建默认帐户和API access tokens。 cloud-controller-manager cloud-controller-manager运⾏着与底层云提供商交互的Controller。cloud-control 04-K8s组件 17 Kubernetes API API conventions doc 中描述了API的总体规范。 API Reference 中描述了API端点、资源类型和样本。 access doc 讨论了API的远程访问。 Kubernetes API也是系统声明式配置模式的基础。 Kubectl 命令⾏⼯具可⽤于创建、更新、删除以及获取API对象。 Kubernetes也会0 码力 | 135 页 | 21.02 MB | 1 年前3
VMware SIG Intro to the vSphere Cloud Providerjoin group: https://groups.google.com/forum/#!forum/kubernetes-sig-vmware (This will give you write access to all the SIG VMware shared google documents) Link to join Slack: https://kubernetes.slack.com0 码力 | 12 页 | 425.38 KB | 1 年前3
共 17 条
- 1
- 2
相关搜索词
秘钥管理TurtlesallthewaydownSecurelymanagingKubernetesSecretsQCon北京2018面向未来面向未来开发部署MichaelChen安全求生指南ApacheOpenWhiskPerfectMatchforYourServerlessPlatform绕过conntrack使用eBPF增强IPVS优化K8s网络性能多雲一體就是現在GOOGLECLOUDKUBERNETES混合雲戰略AmazonElasticServiceEKS探秘基于构建容器平台实践UCloud优刻实验实验室负责叶理灯开源周立VMwareSIGIntrotovSphereCloudProvider













