Mind the Gap! Bringing Together Cloud Services and Managed K8s Environments
May 01, 2023
34 min
Free
kubernetes
cloud-services
aws-eks
azure-aks
gcp-gke
iam
security
server-side-request-forgery
workload-identity
secrets-management
access-control
incident-response
Description
This talk addresses the challenges of integrating managed Kubernetes environments (like EKS, AKS, GKE) with other cloud services such as databases and object storage. Speakers discuss authentication and authorization for both human users and workloads, and techniques for managing external secrets within clusters. They also highlight security risks, including how attackers can pivot from compromised workloads to compromise entire cloud environments, and provide mitigation strategies. The presentation emphasizes leveraging cloud-native identity management and security best practices to build robust applications while avoiding vendor lock-in.