Skip to content

Latest commit

 

History

History
30 lines (21 loc) · 1.65 KB

day09.md

File metadata and controls

30 lines (21 loc) · 1.65 KB

Day 9: Why should developers care about container security?

Video

Day 9: Why should developers care about container security?

About Me

Eric Smalling
Staff Solutions Architect at Chainguard

For about 30 years, I've been an enterprise software developer, architect, and consultant with a focus on CI/CD, DevOps, and container-based solutions over the last decade.

I am also a Docker Captain, and am certified in Kubernetes (CKA, CKAD, CKS), and have been a Docker user since 2013.

Eric Smalling

Description?

Container scanning tools, industry publications, and application security experts are constantly telling us about best practices for how to build our images and run our containers. Often these non-functional requirements seem abstract and are not described well enough for those of us that don’t have an appsec background to fully understand why they are important.

This session explores several of the most common secure container practices, shows examples of how workloads can be exploited if not followed and, most importantly, how to easily find and fix issues when building containers BEFORE you ship them. Additionally, we'll discuss tactics to minimize exploit exposure by hardening runtime container and Kubernetes configurations.

Links referenced in the video