Shrinking Container Images - Security Chaos Engineering with Container Images - Thomas Fricke
About this talk
This talk addresses the challenges of maintaining security in containerized environments, focusing on the messy state of container image content, which often includes disputed CVEs and obsolete software versions. The speaker discusses findings from audits in critical infrastructure, revealing a significant increase in the CVE count and highlighting violations of security principles stemming from broken software build processes for microservices. Rather than placing blame on developers or DevOps teams, this session explores automated strategies to tackle these issues in a DevSecOps framework. Thomas Fricke, an expert with over a decade of experience in containers and Kubernetes, shares insights drawn from his extensive background in security within KRITIS environments, emphasizing the need for agile transformations.
More from this event
See all 108 talks →
Why are we still talking about containers? - Kelsey Hightower at ContainerDays 2025
46:56
Saxo Service Blueprint: Bridging Old and New World with Kubernetes Operators - Jinhong Brejnholt
36:25
Engineering Velocity, Building Trust: DevOps in 2025 - Stephan Stapel
33:17
Getting Started with eBPF Made Easy - Qasim Sarfraz & Michael Friese
33:05