Kubernetes, it's no longer cool, but let's secure it anyway
by Bea Hughes | - 12:45pm
You work for a tech company, you must have at least one Mandatory Kuberenetes™ right?
Wouldn’t it be rad if you turned on a bunch of security options for it? But without it sucking and everything breaking, or having to get developers to do a bunch of work they have no real desire to?
What about if we had fun on the way too? (you know, within reason, this isn’t Mr. Toad’s Wild Ride).
This won’t be “now type this SELinux policy list in to a terminal” in an impossible to read font talk, it won’t be a “Buy this collection of buzzwords and tools you don’t need” talk either. Learn some things about getting your security from zero to some, instead of the typical mythical industry goal of 98% to 99%.
I promise not to mention AI if you don’t, unless you need me to for your boss/professor/parents to sign off for it.
About Bea Hughes
I’m Bea Hughes, blog post author, Dreamwaver, visionary. Plus [former, a long time ago] threat actor. I’ve been lucky enough to work for a bunch of exciting startups, back when that kind of thing was cool, doing security long before it was called infosec. Etsy, Stripe, PagerDuty, so there’s a chance I’ve at least been around people who knew what they were talking about. Maybe it rubbed off. I’ve keynoted DevOpsDays events talking about getting different parts of the business working together. I’ve presented at BsidesNZ on impostor syndrome. SecTor in Toronto. Berlin, London, San Francisco, New York, basically anywhere hipsters congregate (aka, there is good coffee. Well okay, clearly some places slipped through!) I’m known for giving realistic accessible talks. No AI images or text (the spelling would be better if I did). They’ll be jokes along the way, and one day I’ll learn to check the list of sponsors to an event before I upset them.