WeAreDevelopers LIVE • Feb 24, 2022

Enhancing Workload Security in Kubernetes

Dimitrij Klesev , Andreas Zeissner

Think your read-only file systems stop advanced threats? Learn how to defeat fileless malware using kernel-level protections like Seccomp and the Security Profiles Operator in Kubernetes.

Pause
Mute Enter Fullscreen
#1 about 4 min

Introduction to Kubernetes security context configurations

Pod and container specifications can be configured to restrict capabilities, users, and file system access.

#2 about 4 min

Restricting system calls with Seccomp profiles

Applying the least privilege principle mitigates exploits by explicitly denying unnecessary system calls to the kernel.

#3 about 5 min

Extending mandatory access control with AppArmor

AppArmor enables mandatory access control to restrict file access and process isolation across containers sharing a volume.

#4 about 6 min

Tightening the security perimeter using SELinux

SELinux acts as kernel middleware to enforce fine-grained access contexts between subjects and objects.

#5 about 3 min

Automating policies via the Security Profiles Operator

The Security Profiles Operator automates the deployment and management of security module bindings using unified YAML configurations.

#6 about 6 min

Deploying manual Seccomp profiles to block malware

Simulating fileless malware execution in memory demonstrates the necessity of denying specific memory allocation system calls.

#7 about 4 min

Automating Seccomp rules with operator profile bindings

Profile bindings allow administrators to apply Seccomp rules globally without managing static files locally on every node.

#8 about 10 min

Troubleshooting SELinux container permission denials live

Generating custom SELinux policies live helps resolve application directory access denials and permission errors.

#9 about 7 min

Handling container constraints and fileless malware

Audience questions cover granular AppArmor constraints, fileless malware execution techniques, and eBPF as modern kernel middleware.

Matching moments

1:39 min

Introduction to Kubernetes security challenges and opportunities

Marc Nimmerrichter · WWC 2022

1:19 min

Securing Kubernetes workloads and containerized image layers

Aleksandr Kalikov · LIVE

1:54 min

Applying capability constraints in Kubernetes pod specifications

Mathias Tausig · WWC 2023

52 sec

Mitigating container escalation paths using system call filters

Reinhard Kugler · LIVE

4:40 min

Assessing common Kubernetes security incidents and misconfigurations

Rico Komenda Rico Komenda · WWC 2025

11:32 min

Audience questions on security, limitations, and Kubernetes crossover

Maurice Brinkmann · LIVE

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

Run your agents in Kubernetes: Build once, deploy anywhere. But really?

Michal Salanci

Senior Systems Engineer at ESET Cybersecurity

Michal Salanci
Open session

World Congress 2026 North America

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar
Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Context Engineering Kung Fu

Carl Lapierre

Tech Lead and AI Engineer at Osedea

Carl Lapierre