Putting an Invisible Shield on Kubernetes Secretscontents not encrypted (only base64 encoded) • > K8s 1.7+ • at-rest encryption for etcd (local + remote) Local Encryption Provider KMS Encryption Provider Background: K8s Secrets • Encryption Keys to storage in etcd • Secrets decrypted on API Server prior to use • Encryption keys stored in a remote KMS • Use envelope encryption scheme • DEK & KEK Motivation: K8s Secrets Protection • Performance prevented TEE-based KMS Plugin [1] • Address performance & latency concerns • Reduce / minimize remote KMS interactions w/o compromising security • Address security threats • etcd compromise • Host0 码力 | 33 页 | 20.81 MB | 1 年前3
 Advancing the Tactical Edge with K3s and SUSE RGSinformation edge on the battlefield. Booz Allen is transforming military opera- tions in complex and remote locations with the use of groundbreaking technologies, to enable decision-making at the point of Kubernetes distribution, designed for production workloads in unat- tended, resource constrained, remote envi- ronments. This is the story of how, alongside the team at SUSE RGS, Booz Allen is delivering accustomed to thinking about the edge as an enterprise IT term— the edge of the data center, or remote ac- cess capabilities. For Booz Allen, the edge means the far, tactical edge—in the thick of the0 码力 | 8 页 | 888.26 KB | 1 年前3
 Go Programming Pattern in Kubernetes PhilosophyScheduling api-server Etcd bind pod, node list pod GenericRuntime SyncPod CRI grpc dockershim remote (no-op) Sandbox Create Delete List Container Create Start Exec Image Pull List shim client -y kubelet kubeadm kubectl • sed -i '2 i\Environment="KUBELET_EXTRA_ARGS=--container- runtime=remote --container-runtime-endpoint=/var/run/xxx.sock -- feature-gates=AllAlpha=true"' /etc/systemd/system/kubelet0 码力 | 29 页 | 2.12 MB | 1 年前3
 Alluxio 助力 Kubernetes, 加速云端深度学习处 • 支持大规模的数据缓存 • 本地内存加速 • 支持数据预热 • LRU缓存管理 Object storage (Fuse) Worker (local) Worker (remote) Master Training POD Tier0: 1-2GB/S Short Circuit: 1-6GB/S Network: 300M/S Alluxio在Kubernetes上的架构0 码力 | 22 页 | 11.79 MB | 1 年前3
 涂小刚-基于k8s的微服务实践同的监控界面 方案1 方案2 kube-apiserver Metrics-Server metrics-server通过对 api重定向缓存监控进 入内存 pull opentsdb remote_storage_ adapter test-1 test-2 test-3 dev-1 dev-2 dev-3 dev-mysql-1 中间件 dev-redis-1 test-mq-10 码力 | 19 页 | 1.34 MB | 1 年前3
 Jib Kubecon 2018 TalkKubernetes applications. You can iterate on your application source code locally then deploy to local or remote Kubernetes clusters. Skaffold handles the workflow for building, pushing and deploying your application0 码力 | 90 页 | 2.84 MB | 1 年前3
共 6 条
- 1
 













