- Learn Kubernetes Security
- Kaizhe Huang Pranjal Jumde Loris Degioanni
- 215字
- 2021-06-18 18:32:37
Chapter 4: Applying the Principle of Least Privilege in Kubernetes
The principle of least privilege states that each component of an ecosystem should have minimal access to data and resources for it to function. In a multitenant environment, multiple resources can be accessed by different users or objects. The principle of least privilege ensures that damage to the cluster is minimal if users or objects misbehave in such environments.
In this chapter, we will first introduce the principle of least privilege. Given the complexity of Kubernetes, we will first look into the Kubernetes subjects, and then the privileges available for the subjects. Then, we will talk about the privileges of Kubernetes objects and possible ways to restrict them. The goal of this chapter is to help you understand a few critical concepts, such as the principle of least privilege and Role-Based Access Control (RBAC). In this chapter, we will talk about different Kubernetes objects, such as namespaces, service accounts, Roles, and RoleBindings, and Kubernetes security features, such as the security context, the PodSecurityPolicy, and the NetworkPolicy, which can be leveraged to implement the principle of least privilege for your Kubernetes cluster.
In this chapter, we will cover the following topics:
- The principle of least privilege
- Least privilege of Kubernetes subjects
- Least privilege of Kubernetes workloads
- 一本書學內部審計:新手內部審計從入門到精通
- 中國新股民必讀手冊(2015年最新版)
- 金融科技(FinTech)發展的國際經驗和中國政策取向(中國金融四十人論壇書系)
- 自愿審計動機與質量研究:基于我國中期財務報告審計的經驗證據
- 基于價值增值的治理導向型內部審計研究
- Citrix? XenMobile? Mobile Device Management
- 國家治理能力視角的國家審計功能理論研究
- 項目管理(第二版)
- Big Data Visualization
- Microsoft System Center Data Protection Manager 2012 SP1
- 非線性經濟關系的建模
- Minitab Cookbook
- Stata統計分析與行業應用案例詳解(第2版)
- Business Intelligence Cookbook:A Project Lifecycle Approach Using Oracle Technology
- 計量經濟學理論與應用:基于Eviews的應用分析