May 2-4, 2018 - Copenhagen, Denmark
Click Here For Information & Registration
Back To Schedule
Friday, May 4 • 11:55 - 12:30
From Kubelet to Istio: Kubernetes Network Security Demystified - Andrew Martin, ControlPlane (Intermediate Skill Level) (Slides Attached)

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
Kubernetes provides multiple layers of network security including the control plane, etcd, the CNI network, network policies, and - with Istio on top - the requests between applications themselves. In this talk we explore the underlying technologies on which these layers are built using approachable examples and demonstrations. Attendees can expect to gain an understanding of these implementations and the principles behind encryption, identity, and trust in Kubernetes.
- What are TLS, X.509, and mutual authentication?
- Why cloud native communication should be encrypted by default
- Kubernetes component intercommunication
- CNI and network policy for applications
- Bootstrapping identity with SPIFFE
- Mutual TLS, route rules, and destination policies in Istio

avatar for Andrew Martin

Andrew Martin

CEO, ControlPlane
Andrew has an incisive security engineering ethos gained building and destroying high-traffic web applications. Proficient in systems development, testing, and operations, he is at his happiest profiling and securing every tier of a cloud native system, and has battle-hardened experience... Read More →

Friday May 4, 2018 11:55 - 12:30 CEST
  Security+Identity+Signing, Intermediate