- Learn Kubernetes Security
- Kaizhe Huang Pranjal Jumde Loris Degioanni
- 215字
- 2021-06-18 18:32:37
Chapter 4: Applying the Principle of Least Privilege in Kubernetes
The principle of least privilege states that each component of an ecosystem should have minimal access to data and resources for it to function. In a multitenant environment, multiple resources can be accessed by different users or objects. The principle of least privilege ensures that damage to the cluster is minimal if users or objects misbehave in such environments.
In this chapter, we will first introduce the principle of least privilege. Given the complexity of Kubernetes, we will first look into the Kubernetes subjects, and then the privileges available for the subjects. Then, we will talk about the privileges of Kubernetes objects and possible ways to restrict them. The goal of this chapter is to help you understand a few critical concepts, such as the principle of least privilege and Role-Based Access Control (RBAC). In this chapter, we will talk about different Kubernetes objects, such as namespaces, service accounts, Roles, and RoleBindings, and Kubernetes security features, such as the security context, the PodSecurityPolicy, and the NetworkPolicy, which can be leveraged to implement the principle of least privilege for your Kubernetes cluster.
In this chapter, we will cover the following topics:
- The principle of least privilege
- Least privilege of Kubernetes subjects
- Least privilege of Kubernetes workloads
- 中國新股民必讀手冊(2015年最新版)
- 汪博士詳解PMP?模擬題(第4版)
- 基本有用的計量經濟學
- 財務建模與綜合估值:數據研磨、模型校準、動態估值
- Getting Started with Citrix VDI-in-a-Box
- 振蕩指標MACD:波段操作精解(升級版)
- vSphere Design Best Practices
- Minitab Cookbook
- PMP備考寶典:路晨帶你去通關
- Business Intelligence Cookbook:A Project Lifecycle Approach Using Oracle Technology
- 計量經濟學
- Microsoft Dynamics CRM 2016 Customization(Second Edition)
- QlikView for Developers Cookbook
- 人口預測模型研究及應用
- 政府采購評審專家工作指南