Loading…
Wednesday, March 20 • 15:25 - 16:00
Safety or Usability: Why Not Both? Towards Referential Auth in K8s - Rob Scott, Google & Mo Khan, Microsoft

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.


Is your essential tooling leaving your Kubernetes clusters vulnerable to CVEs? Are you sure? For example, Ingress and Gateway controllers are often deployed with read access to all Secrets in a cluster. What if we could introduce new authorization APIs that both mitigate future CVEs and enable entirely new reference patterns? In this talk, Rob and Mo will show how new APIs being developed by the community can help keep your clusters secure and safely enable cross-namespace references. Along the way, you’ll learn the history of these problems, including various stop-gap solutions that have been attempted along the way, to help you understand the context for the proposed changes. This session will provide you with clear guidelines for how to keep your clusters secure today by limiting unnecessary access to components running in your clusters. You’ll also learn how you can shape the future of these Kubernetes APIs by providing early feedback in the coming months of active development.

Speakers
avatar for Mo Khan

Mo Khan

Software Engineer, Microsoft
Mo Khan is a software engineer who is passionate about open source and security. He started working on Kubernetes in 2016, and currently serves as a chair, technical lead and subproject owner for Kubernetes SIG Auth, a member of the Kubernetes Security Response Committee and a contributor... Read More →
avatar for Rob Scott

Rob Scott

Software Engineer, Google
Rob is an open source enthusiast currently working on Kubernetes Networking at Google. He's been a maintainer of Gateway API since the very early days of the project and led the development of other Kubernetes networking APIs like EndpointSlices.



Wednesday March 20, 2024 15:25 - 16:00 CET
Pavilion 7 | Level 7.1 | Room D
  Security