About this talk
This talk covers practical experiences in implementing security measures for critical infrastructure projects, particularly in the context of cloud-native environments that are highly regulated. The speaker shares insights from real-world projects in Germany and Europe where Kubernetes is utilized to manage applications integral to infrastructure control. Key topics include container hardening techniques, strategies for encouraging developers to create compliant containers, and integrating security team members into DevOps practices. The session also explores CI/CD pipelines involving third-party vendors, air-gapped cloud-native architectures, and the importance of achieving the highest availability for running clusters.
More from this event
See all 9 talks →
Let's talk how fast a multi-layered Attack in the Cloud can look like - Stefan Trimborn, Sysdig
25:06
Solving ‘secret zero’, why you should care about SPIFFE! - Matt Barker & Mattias Gees, Venafi
33:23
This is a complete Disaster(-recovery) – Protecting Kubernetes from Fail - Benjamin Ritter
27:56
Adventures in the Kernel: Using eBPF and Tetragon for runtime visibility - Jeremy Colvin, Isovalent
29:46