talk-data.com talk-data.com

R

Speaker

Rafael Natali

1

talks

Lead DevSecOps Marionete

Rafael Natali has 20 years of experience in the IT industry, specifically as a System Administrator and DevSecOps professional. He has developed extensive knowledge in designing, operating, and troubleshooting solutions that prioritize scalability and reliability. He is also an expert in Automation as well as Continuous Integration and Delivery.

Bio from: I Fought the Pod and the Pod Won: Breaking and Defending Kubernetes from Within

Filtering by: I Fought the Pod and the Pod Won: Breaking and Defending Kubernetes from Within ×

Filter by Event / Source

Talks & appearances

Showing 1 of 2 activities

Search activities →

Kubernetes gives us abstraction and power—but with great YAML comes great responsibility. In this talk, we’ll walk through live demos of real-world misconfigurations that allow attackers to escape containers and tamper with the host. You’ll see exactly what happens when Pods run in privileged mode, use hostPath volumes carelessly, or retain excess Linux capabilities. We’ll also show how to detect these attacks in real time using Falco, and enforce safety nets with Pod Security Admission. If you’ve ever wondered "what’s the worst that could happen?"—this session answers that with receipts.