SlideShare a Scribd company logo
Hardening Against
Kubernetes Hacks
Live Demo
Eric Smalling
Sr. Developer Advocate | Snyk.io
about.me/ericsmalling
2
ERIC SMALLING
● Senior Developer Advocate @ Snyk
● Based in Dallas/Fort Worth, Texas
● 20+ years enterprise software development
● 10+ years build/test/deploy automation (CI/CD)
● Docker user since 2013 (v0.6)
● 2018 Jenkins Ambassador
● Docker Captain
● CKA, CKAD & CKS Certified
3
00 Section Header
Exploit
=
App Vulns + Misconfiguration
4
https://github.com/snyk-labs/kubernetes-goof
DEMO
https://github.com/snyk-labs/kubernetes-goof
DockerCon 2023 - Live Demo_Hardening Against Kubernetes Hacks.pdf
7
How could we have
prevented this?
● Scan your application code
● Scan your container images
● Scan your Kubernetes YAML
● Don’t trust defaults / Be explicit
● Use Network Policies
● Use Admission Controls
8
Thanks and props to :
● Mark Manning ( @antitree )
● Ian Coldwater ( @iancoldwater )
● DuïŹ€ie Cooley ( @mauilion )
● Rory McCune ( @raesene )
● K8s SIG-Security
● CNCF TAG-Security
● OpenSSF

 and many others in the Kubernetes Security community.
THANK YOU
https://github.com/snyk-labs/kubernetes-goof
about.me/ericsmalling

More Related Content

PDF
KubeCon NA 2022 - Hardening against Kubernetes Hacks.pdf
PDF
Hacking into your containers, and how to stop it!
PDF
Kubernetes 101 for_penetration_testers_-_null_mumbai
PDF
GDG SLK - Why should devs care about container security.pdf
PDF
DevOpsDays Chicago 2022 - Hands-on hacking containers and ways to prevent it
PDF
Securing k8s With Kubernetes Goat
PDF
Lines of Defense - Securing your Kubernetes Clusters by Koray Oksay
PPTX
12 Ways Not to get 'Hacked' your Kubernetes Cluster
KubeCon NA 2022 - Hardening against Kubernetes Hacks.pdf
Hacking into your containers, and how to stop it!
Kubernetes 101 for_penetration_testers_-_null_mumbai
GDG SLK - Why should devs care about container security.pdf
DevOpsDays Chicago 2022 - Hands-on hacking containers and ways to prevent it
Securing k8s With Kubernetes Goat
Lines of Defense - Securing your Kubernetes Clusters by Koray Oksay
12 Ways Not to get 'Hacked' your Kubernetes Cluster

Similar to DockerCon 2023 - Live Demo_Hardening Against Kubernetes Hacks.pdf (20)

PDF
Why should developers care about container security?
PPTX
Kubernetes Security
PDF
LFX Nov 16, 2021 - Find vulnerabilities before security knocks on your door
PDF
Stanislav Kolenkin & Igor Khoroshchenko - Knock Knock: Security threats with ...
PDF
DevSecCon Lightning 2021- Container defaults are a hackers best friend
PDF
Breaking the Kubernetes Kill Chain: Host Path Mount
PPTX
10 tips for Cloud Native Security
PDF
Hardening Kubernetes Cluster
PPTX
Secure development on Kubernetes by Andreas Falk
PDF
CloudNativeTurkey - Lines of Defence.pdf
PDF
The Hacker's Guide to Kubernetes
PDF
All Your Containers Are Belong To Us
PPTX
DevSecOps in a cloudnative world
PPTX
Simplify Your Way To Expert Kubernetes Management
PPTX
Kubernetes and container security
PDF
Attacking and Defending Kubernetes - Nithin Jois
PDF
K8 Meetup_ K8s secrets management best practices (Git Guardian).pdf
PDF
Why Should Developers Care About Container Security?
PDF
ATO 2022 - Why should devs care about container security.pdf
PDF
Container Stranger Danger - Why should devs care about container security
Why should developers care about container security?
Kubernetes Security
LFX Nov 16, 2021 - Find vulnerabilities before security knocks on your door
Stanislav Kolenkin & Igor Khoroshchenko - Knock Knock: Security threats with ...
DevSecCon Lightning 2021- Container defaults are a hackers best friend
Breaking the Kubernetes Kill Chain: Host Path Mount
10 tips for Cloud Native Security
Hardening Kubernetes Cluster
Secure development on Kubernetes by Andreas Falk
CloudNativeTurkey - Lines of Defence.pdf
The Hacker's Guide to Kubernetes
All Your Containers Are Belong To Us
DevSecOps in a cloudnative world
Simplify Your Way To Expert Kubernetes Management
Kubernetes and container security
Attacking and Defending Kubernetes - Nithin Jois
K8 Meetup_ K8s secrets management best practices (Git Guardian).pdf
Why Should Developers Care About Container Security?
ATO 2022 - Why should devs care about container security.pdf
Container Stranger Danger - Why should devs care about container security

More from Eric Smalling (12)

PDF
KubeHuddle NA 2023 - Why should devs care about container security - Eric Sma...
PDF
Look Ma' - Building Java and Go based container images without Dockerfiles
PDF
SCaLE 19x - Eric Smalling - Hardening against Kubernetes Hacks
PDF
DockerCon 2022 - From legacy to Kubernetes, securely & quickly
PDF
Python Web Conference 2022 - Why should devs care about container security.pdf
PDF
AWS live hack: Docker + Snyk Container on AWS
PDF
AWS live hack: Atlassian + Snyk OSS on AWS
PDF
So. many. vulnerabilities. Why are containers such a mess and what to do abou...
PDF
IBM Index 2018 Conference Workshop: Modernizing Traditional Java App's with D...
PDF
Best Practices for Developing & Deploying Java Applications with Docker
PDF
Docker 101 Workshop slides (JavaOne 2017)
PPTX
Simply your Jenkins Projects with Docker Multi-Stage Builds
KubeHuddle NA 2023 - Why should devs care about container security - Eric Sma...
Look Ma' - Building Java and Go based container images without Dockerfiles
SCaLE 19x - Eric Smalling - Hardening against Kubernetes Hacks
DockerCon 2022 - From legacy to Kubernetes, securely & quickly
Python Web Conference 2022 - Why should devs care about container security.pdf
AWS live hack: Docker + Snyk Container on AWS
AWS live hack: Atlassian + Snyk OSS on AWS
So. many. vulnerabilities. Why are containers such a mess and what to do abou...
IBM Index 2018 Conference Workshop: Modernizing Traditional Java App's with D...
Best Practices for Developing & Deploying Java Applications with Docker
Docker 101 Workshop slides (JavaOne 2017)
Simply your Jenkins Projects with Docker Multi-Stage Builds

Recently uploaded (20)

PPTX
VVF-Customer-Presentation2025-Ver1.9.pptx
PPTX
ISO 45001 Occupational Health and Safety Management System
PDF
Wondershare Filmora 15 Crack With Activation Key [2025
PPTX
Introduction to Artificial Intelligence
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PPTX
CHAPTER 2 - PM Management and IT Context
PDF
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
PDF
Understanding Forklifts - TECH EHS Solution
PDF
Odoo Companies in India – Driving Business Transformation.pdf
PDF
Nekopoi APK 2025 free lastest update
PDF
2025 Textile ERP Trends: SAP, Odoo & Oracle
PPTX
ManageIQ - Sprint 268 Review - Slide Deck
PDF
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
PDF
System and Network Administraation Chapter 3
PDF
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
PDF
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
PDF
Design an Analysis of Algorithms II-SECS-1021-03
PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PDF
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
PPTX
Operating system designcfffgfgggggggvggggggggg
VVF-Customer-Presentation2025-Ver1.9.pptx
ISO 45001 Occupational Health and Safety Management System
Wondershare Filmora 15 Crack With Activation Key [2025
Introduction to Artificial Intelligence
Design an Analysis of Algorithms I-SECS-1021-03
CHAPTER 2 - PM Management and IT Context
Addressing The Cult of Project Management Tools-Why Disconnected Work is Hold...
Understanding Forklifts - TECH EHS Solution
Odoo Companies in India – Driving Business Transformation.pdf
Nekopoi APK 2025 free lastest update
2025 Textile ERP Trends: SAP, Odoo & Oracle
ManageIQ - Sprint 268 Review - Slide Deck
Internet Downloader Manager (IDM) Crack 6.42 Build 42 Updates Latest 2025
System and Network Administraation Chapter 3
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
Raksha Bandhan Grocery Pricing Trends in India 2025.pdf
Design an Analysis of Algorithms II-SECS-1021-03
Navsoft: AI-Powered Business Solutions & Custom Software Development
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
Operating system designcfffgfgggggggvggggggggg

DockerCon 2023 - Live Demo_Hardening Against Kubernetes Hacks.pdf