Glossary
#Falco - Host Intrusion Detection tool (only log the detection)
#seccomp - restrict system calls within a container
...
securityContext:
seccompProfile:
type: RuntimeDefault#AppArmour - a layer between userspace and kernel syscalls
#Network Policy
#Ingress
#CIS Center for Internet Security (secure OS)
#CIS Benchmark (secure Kubernetes)
#ETCD - Encrypting Secret Data at Rest
Name
Encryption
Strength
Speed
Key Length
Other Considerations
#Container Runtime Sandboxes ????
#Security Contexts
#Open Policy Agent and Gatekeeper (OPA)
#Image footprint (security)
#Static Analysis
kubesec run as:
#Image Vulnerability Scanning
#Secure supply chain
Kubernetes - private registry
Whitelist Registries with OPA Gatekeeeper
ImagePolicyWenhook
Last updated