ironing out Docker
at ironPeak services
ironpeak.be
ironing out Docker at ironPeak services ironpeak.be 1. $ whoami - - PowerPoint PPT Presentation
ironing out Docker at ironPeak services ironpeak.be 1. $ whoami Niels Hofmans role Independent Cybersecurity Consultant work Code Security, App Security, Hardening, F5 BIG-IP interest Go, Docker, Cloud, Media contact hello@ironpeak.be
ironpeak.be
1 - whoami
ironpeak.be
role Independent Cybersecurity Consultant work Code Security, App Security, Hardening, F5 BIG-IP interest Go, Docker, Cloud, Media contact hello@ironpeak.be github github.com/HazCod
2 - tree
ironpeak.be
user host image Runtime
3 - client
ironpeak.be
The Client (you!)
3 - client
ironpeak.be
The Client (you!)
3 - client
ironpeak.be
The Client (you!)
4 - host
ironpeak.be
Host hardening
Daemon hardening
4 - host
ironpeak.be
Daemon Access
Host Auditing
e.g. sysdig.org + falco.org, github.com/netdata/netdata Private Registry
5 - image
ironpeak.be
github.com/GoogleContainerTools/distroless
5 - image
ironpeak.be
Dockerfile
5 - image
ironpeak.be
5 - image
ironpeak.be
USER?
5 - image
ironpeak.be
6 - runtime
ironpeak.be
Container Runtime Properties
6 - runtime
ironpeak.be
Application Security
7 - exit
ironpeak.be
https://ironpeak.be/slides/190319-ironing-out-docker.pdf