WeAreDevelopers LIVE • Feb 24, 2022

Enhancing Workload Security in Kubernetes

Dimitrij Klesev , Andreas Zeissner

Think your read-only file systems stop advanced threats? Learn how to defeat fileless malware using kernel-level protections like Seccomp and the Security Profiles Operator in Kubernetes.

Pause
Mute Enter Fullscreen
#1 about 4 min

Introduction to Kubernetes security context configurations

Pod and container specifications can be configured to restrict capabilities, users, and file system access.

#2 about 4 min

Restricting system calls with Seccomp profiles

Applying the least privilege principle mitigates exploits by explicitly denying unnecessary system calls to the kernel.

#3 about 5 min

Extending mandatory access control with AppArmor

AppArmor enables mandatory access control to restrict file access and process isolation across containers sharing a volume.

#4 about 6 min

Tightening the security perimeter using SELinux

SELinux acts as kernel middleware to enforce fine-grained access contexts between subjects and objects.

#5 about 3 min

Automating policies via the Security Profiles Operator

The Security Profiles Operator automates the deployment and management of security module bindings using unified YAML configurations.

#6 about 6 min

Deploying manual Seccomp profiles to block malware

Simulating fileless malware execution in memory demonstrates the necessity of denying specific memory allocation system calls.

#7 about 4 min

Automating Seccomp rules with operator profile bindings

Profile bindings allow administrators to apply Seccomp rules globally without managing static files locally on every node.

#8 about 10 min

Troubleshooting SELinux container permission denials live

Generating custom SELinux policies live helps resolve application directory access denials and permission errors.

#9 about 7 min

Handling container constraints and fileless malware

Audience questions cover granular AppArmor constraints, fileless malware execution techniques, and eBPF as modern kernel middleware.

Matching moments

1:39 min

Introduction to Kubernetes security challenges and opportunities

Marc Nimmerrichter · World Congress 2022

1:19 min

Securing Kubernetes workloads and containerized image layers

Aleksandr Kalikov · LIVE

1:54 min

Applying capability constraints in Kubernetes pod specifications

Mathias Tausig · World Congress 2023

52 sec

Mitigating container escalation paths using system call filters

Reinhard Kugler · LIVE

4:40 min

Assessing common Kubernetes security incidents and misconfigurations

Rico Komenda Rico Komenda · World Congress 2025

11:32 min

Audience questions on security, limitations, and Kubernetes crossover

Maurice Brinkmann · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 2

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 10

Securing the Agentic Stack: Docker Hardened Images and Supply Chain Security

Ajeet Raina

Developer Advocate, Docker

Ajeet Raina
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Mainstage

One Boundary for the Agentic Era

Mark Lechner

Chief Information Security Officer, Dokcer

Mark Lechner
Open session

World Congress 2026 North America

September 25, 2026 · 12:30–14:30

Stage 11

Docker sandboxes: protect your secrets, tokens, and personal data from AI agent mistakes

Kristiyan Velkov

Front-End Advocate | Speaker | AI & DevOps | Docker Captain | Cursor Ambassador | DevReal | Tech Blogger | Book Author

Kristiyan Velkov
Open session

World Congress 2026 North America

September 24, 2026 · 15:30–16:00

Stage 9

Run your agents in Kubernetes: Build once, deploy anywhere. But really?

Michal Salanci

Senior Systems Engineer at ESET Cybersecurity

Michal Salanci
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 8

Docker's Agentic Platform: Sandboxes, MCP, and the Infrastructure of Autonomous Development

Oleg Å elajev

AI and Developer relations at Docker

Oleg Å elajev