Artwork

Content provided by podcast_v0.1. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by podcast_v0.1 or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Locking Down Kubernetes: CERN’s Guide to Network Policies, OPA & Vault

14:20
 
Share
 

Manage episode 480893310 series 3662367
Content provided by podcast_v0.1. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by podcast_v0.1 or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Discover how CERN secures the vital Kubernetes cluster powering its massive CMS particle physics experiment using key cloud-native tools. This episode explores their real-world implementation of Network Policies via Calico for fine-grained internal firewalling between microservices. We delve into their use of Open Policy Agent (OPA) Gatekeeper to enforce custom rules on resource creation, ensuring compliance *before* deployment. Understand their shift to HashiCorp Vault for robust, centralized, and encrypted secrets management, moving beyond basic K8s secrets. Learn how these technologies form a layered defense strategy against modern threats. We also cover practical details like specific OPA policies and the seamless Vault Agent Injector pattern.
Read the original paper: http://arxiv.org/abs/2405.15342v1
Music: 'The Insider - A Difficult Subject'
  continue reading

15 episodes

Artwork
iconShare
 
Manage episode 480893310 series 3662367
Content provided by podcast_v0.1. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by podcast_v0.1 or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Discover how CERN secures the vital Kubernetes cluster powering its massive CMS particle physics experiment using key cloud-native tools. This episode explores their real-world implementation of Network Policies via Calico for fine-grained internal firewalling between microservices. We delve into their use of Open Policy Agent (OPA) Gatekeeper to enforce custom rules on resource creation, ensuring compliance *before* deployment. Understand their shift to HashiCorp Vault for robust, centralized, and encrypted secrets management, moving beyond basic K8s secrets. Learn how these technologies form a layered defense strategy against modern threats. We also cover practical details like specific OPA policies and the seamless Vault Agent Injector pattern.
Read the original paper: http://arxiv.org/abs/2405.15342v1
Music: 'The Insider - A Difficult Subject'
  continue reading

15 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide

Listen to this show while you explore
Play