SlideShare a Scribd company logo
1
PAGE
1
DEVOPS INDONESIA
Zhihao Tan
DevOps Community in Indonesia
Jakarta, 20 April 2020
Secure your Containers within 30 minutes
© 2019 Aqua Security Software Ltd., All Rights Reserved
Zhihao TAN - Senior Solution Architect, Aqua Security
Secure your containers in 30 minutes!
3
 Container Security Landscape
 6 top container security concerns
 How Aqua addresses these concerns
 Q&A
Agenda
4
What’s the deal?
5
Container Confidence
6
And DevOps agree…
Source: Portworx & Aqua survey, May 2019 (n=501)
7
DevSecOps…?
8
Problem #1 Open Source Supply Chain Attacks
9
Problem #2 Built-in Weaknesses
10
Problem #3 Infrastructure Flaws
11
Problem #4 The Hidden Network
Existing Network Defenses
Infrastructure /
Security Admins
Multiple CI/CD SIEM / Analytics
Kubernetes
Clusters
CaaS
Services
Linux/WindowsOS
Azure AKS
Google GKE
ContainerEngine
Workloads (e.g. AWS / Azure / Google)
Azure ACI Container
AWS ECS / Fargate Container
Public
Registry
Private
Registry
Problem #5 Multi-Cloud / Multi-Platform Challenges
AWS EKS
Serverless
Functions
Azure Functions
AWS Lambda Functions
Center
Enterprise Cloud
13
Problem #6 DevSecOps!
14
Specific controls
Stacking controls over time
Secure the
Infrastructure
Baseline
Environment
Secure the build
Secure the
workloads
• Secure the cloud
infrastructure
• Understand current state
• Container Immutability
• Virtual Patching
• Image Hygiene
• Dynamic Analysis
• Admission Control
• Container firewall
• Secrets management
General controls
Continuous Security & Continuous Compliance
InfrastructureandWorkloadSecurity
DEMO
16
 Get immediate value from Aqua in the first 30 minutes
 Environment Discovery
 Container Immutability with Drift Prevention
 vShield
 Developer flexibility and velocity
 Discovery of the unknown
 Dynamic scanning with Dynamic Threat Analysis (Ultrabox)
 Automate admission control
 Security of workloads with fine-grained runtime controls
Key take-aways
17
DevSecOps!
NEXT STEPS?
Use free Aqua tools!
19
Aqua OpenSource - With free stuff!
 Scans Kubernetes nodes
against the CIS benchmark
checks
 github.com/aquasecurity/kube-
bench
CIS benchmark for K8S
 Scan Docker build for known
vulnerabilities
 Plugs easily into CI/CD tools
 github.com/aquasecurity/trivy
Docker image scanner K8S penetration testing
 Tests K8s clusters against
known attack vectors
 github.com/aquasecurity/kub
e-hunter
ZHIHAO.TAN@AQUASEC.COM
 Scan cloud accounts for
vulnerabilities
 Opensource / Open-core
 https://cloud.aquasec.com/signup
Infrastructure scanner
Stay Connected
@devopsindonesia
http://www.devopsindonesia.com
@IDDevOps
@DevOpsIndonesia
@IDDevOps
Zhihao Tan Mail :
zhihao.tan@aquasec.com
Alone We are smart, together We are brilliant
THANKYOU !
Quote by Steve Anderson

More Related Content

PDF
Scaling DevSecOps Culture for Enterprise
PDF
Dockercon 2018 Announcement
PPTX
DockerCon EU 2017 - General Session Day 1
PPTX
Introduction to KubeSphere and its open source ecosystem
PDF
How we can do Multi-Tenancy on Kubernetes
PPTX
DockerCon EU 2017 Recap
PDF
DCSF19 Kubernetes Security with OPA
PDF
DCSF19 Adding a Modern API Layer to ‘Dockerized’ Legacy Apps
Scaling DevSecOps Culture for Enterprise
Dockercon 2018 Announcement
DockerCon EU 2017 - General Session Day 1
Introduction to KubeSphere and its open source ecosystem
How we can do Multi-Tenancy on Kubernetes
DockerCon EU 2017 Recap
DCSF19 Kubernetes Security with OPA
DCSF19 Adding a Modern API Layer to ‘Dockerized’ Legacy Apps

What's hot (20)

PDF
DCSF 19 Improving the Human Condition with Docker
PPTX
DockerCon 2017 - General Session Day 2 - Ben Golub
PDF
Is your kubernetes negative or positive
PDF
Javantura v4 - Cloud-native Architectures and Java - Matjaž B. Jurič
PDF
Olivier meetup-boston-2013-jan-21-v2
PDF
Platform for a Connected World
PPTX
Practical Approaches to Cloud Native Security
PDF
From Monolith to K8s - Spring One 2020
PDF
Data protection in a kubernetes-native world
PDF
Elevate Your Enterprise Python and R AI, ML Software Strategy with Anaconda T...
PDF
Fully Orchestrating Applications, Microservices and Enterprise Services with ...
PDF
Okteto For Kubernetes Developer :- Container Camp 2020
PDF
Docker Birthday #5 Meetup Cluj - Presentation
PPTX
Microservices, docker , kubernetes and many more
PPTX
Docker 之道 Modernize Traditional Applications with 无为 Create New Cloud Native ...
PDF
Making Friendly Microservices by Michele Titlol
PPTX
Running database infrastructure on containers
PPTX
Distributed Storage in the Cloud
PDF
Tampere Docker meetup - Happy 5th Birthday Docker
PDF
Spring Boot Observability
DCSF 19 Improving the Human Condition with Docker
DockerCon 2017 - General Session Day 2 - Ben Golub
Is your kubernetes negative or positive
Javantura v4 - Cloud-native Architectures and Java - Matjaž B. Jurič
Olivier meetup-boston-2013-jan-21-v2
Platform for a Connected World
Practical Approaches to Cloud Native Security
From Monolith to K8s - Spring One 2020
Data protection in a kubernetes-native world
Elevate Your Enterprise Python and R AI, ML Software Strategy with Anaconda T...
Fully Orchestrating Applications, Microservices and Enterprise Services with ...
Okteto For Kubernetes Developer :- Container Camp 2020
Docker Birthday #5 Meetup Cluj - Presentation
Microservices, docker , kubernetes and many more
Docker 之道 Modernize Traditional Applications with 无为 Create New Cloud Native ...
Making Friendly Microservices by Michele Titlol
Running database infrastructure on containers
Distributed Storage in the Cloud
Tampere Docker meetup - Happy 5th Birthday Docker
Spring Boot Observability
Ad

Similar to Secure your container within 30 minutes (20)

PPTX
Docker Bday #5, SF Edition: Introduction to Docker
PPTX
Outpost24 webinar mastering container security in modern day dev ops
PDF
Securing Your Containers is Not Enough: How to Encrypt Container Data
PPTX
DockerCon EU 2015: Nesting Containers: Real Life Observations
PPTX
DoD Enterprise DevSecOps Initiative by Mr. Nicolas Chaillan
PPTX
Migration from Java EE to JakartaEE 10 - Challenges & Opportunities
PPTX
d2iq, d2iq konvoy, day 2 operations, lifecycle management, mayadata, mayadata...
PDF
Implementing DevOps – How it came to the fore, its key elements and example d...
PDF
The Future of Cloud Innovation, featuring Adrian Cockcroft
PPTX
2024-09-10 Jacksonville JUG Java on Azure with AI
PDF
DockerPenang Meetup#1
PPTX
JCON_15FactorWorkshop.pptx
PDF
Mastering VPC Architecture Build for Scale from Day 1.pdf
PPTX
Enterprise level cloud CI
PDF
Docker
PPTX
Docker EE 2.0 choice security agility by Erik Tan,Tech Insights Singapore - 2...
PDF
Top 7 Benefits & Features of .NET Framework For Developers
PDF
Paris Container Day 2016 : How cluster managers affect the landscape of moder...
PDF
Docker Birthday #3 Slides - Overview
PDF
Docker Birthday #3 - Intro to Docker Slides
Docker Bday #5, SF Edition: Introduction to Docker
Outpost24 webinar mastering container security in modern day dev ops
Securing Your Containers is Not Enough: How to Encrypt Container Data
DockerCon EU 2015: Nesting Containers: Real Life Observations
DoD Enterprise DevSecOps Initiative by Mr. Nicolas Chaillan
Migration from Java EE to JakartaEE 10 - Challenges & Opportunities
d2iq, d2iq konvoy, day 2 operations, lifecycle management, mayadata, mayadata...
Implementing DevOps – How it came to the fore, its key elements and example d...
The Future of Cloud Innovation, featuring Adrian Cockcroft
2024-09-10 Jacksonville JUG Java on Azure with AI
DockerPenang Meetup#1
JCON_15FactorWorkshop.pptx
Mastering VPC Architecture Build for Scale from Day 1.pdf
Enterprise level cloud CI
Docker
Docker EE 2.0 choice security agility by Erik Tan,Tech Insights Singapore - 2...
Top 7 Benefits & Features of .NET Framework For Developers
Paris Container Day 2016 : How cluster managers affect the landscape of moder...
Docker Birthday #3 Slides - Overview
Docker Birthday #3 - Intro to Docker Slides
Ad

More from DevOps Indonesia (20)

PDF
DevSecOps Implementation Journey
PDF
DevOps Indonesia X Palo Alto and Dkatalis Roadshow to DevOpsDays Jakarta 2022
PDF
Securing an NGINX deployment for K8s
PDF
DevOps Indonesia Meetup #52 - announcement
PDF
Dev ops meetup 51 : Securing DevOps Lifecycle - Announcement
PDF
Securing DevOps Lifecycle
PDF
DevOps Meetup 50 : Securing your Application - Announcement
PDF
Secure your Application with Google cloud armor
PDF
DevOps Meetup 49 Aws Copilot and Gitops - announcement by DevOps Indonesia
PDF
Operate Containers with AWS Copilot
PDF
Continuously Deploy Your CDK Application by Petra novandi barus
PDF
DevOps indonesia (online) meetup 46 aws with payfazz in devops indonesia - a...
PDF
Securing Your Database Dynamic DB Credentials
PDF
DevOps Indonesia (online) meetup 45 - Announcement
PDF
The Death and Rise of Enterprise DevOps
PDF
API Security Webinar - Credential Stuffing
PDF
API Security Webinar - Security Guidelines for Providing and Consuming APIs
PDF
API Security Webinar - Hendra Tanto
PDF
API Security Webinar : Credential Stuffing
PDF
API Security Webinar : Security Guidelines for Providing and Consuming APIs
DevSecOps Implementation Journey
DevOps Indonesia X Palo Alto and Dkatalis Roadshow to DevOpsDays Jakarta 2022
Securing an NGINX deployment for K8s
DevOps Indonesia Meetup #52 - announcement
Dev ops meetup 51 : Securing DevOps Lifecycle - Announcement
Securing DevOps Lifecycle
DevOps Meetup 50 : Securing your Application - Announcement
Secure your Application with Google cloud armor
DevOps Meetup 49 Aws Copilot and Gitops - announcement by DevOps Indonesia
Operate Containers with AWS Copilot
Continuously Deploy Your CDK Application by Petra novandi barus
DevOps indonesia (online) meetup 46 aws with payfazz in devops indonesia - a...
Securing Your Database Dynamic DB Credentials
DevOps Indonesia (online) meetup 45 - Announcement
The Death and Rise of Enterprise DevOps
API Security Webinar - Credential Stuffing
API Security Webinar - Security Guidelines for Providing and Consuming APIs
API Security Webinar - Hendra Tanto
API Security Webinar : Credential Stuffing
API Security Webinar : Security Guidelines for Providing and Consuming APIs

Recently uploaded (20)

PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Electronic commerce courselecture one. Pdf
PPTX
Machine Learning_overview_presentation.pptx
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PDF
Chapter 3 Spatial Domain Image Processing.pdf
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
MIND Revenue Release Quarter 2 2025 Press Release
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
A comparative analysis of optical character recognition models for extracting...
PPT
Teaching material agriculture food technology
PPTX
sap open course for s4hana steps from ECC to s4
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
20250228 LYD VKU AI Blended-Learning.pptx
Electronic commerce courselecture one. Pdf
Machine Learning_overview_presentation.pptx
NewMind AI Weekly Chronicles - August'25-Week II
Chapter 3 Spatial Domain Image Processing.pdf
Advanced methodologies resolving dimensionality complications for autism neur...
Building Integrated photovoltaic BIPV_UPV.pdf
MIND Revenue Release Quarter 2 2025 Press Release
The AUB Centre for AI in Media Proposal.docx
A comparative analysis of optical character recognition models for extracting...
Teaching material agriculture food technology
sap open course for s4hana steps from ECC to s4
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
MYSQL Presentation for SQL database connectivity
Programs and apps: productivity, graphics, security and other tools
Per capita expenditure prediction using model stacking based on satellite ima...
Agricultural_Statistics_at_a_Glance_2022_0.pdf
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf

Secure your container within 30 minutes