SlideShare a Scribd company logo
Google Cloud Container Security QuickView
Lightning talk of 5-10 minutes....
Krishna Kumar – CNCF Ambassador
Google Cloud Security – Console View – First Look
https://console.cloud.google.com/
Google Compute Engine Security

Google cloud Identity service - IAM

IAM Policies & Organization level
policies

Effectively design the hierarchy

Apply Leave privileaged access policy
mode

Create security groups with conceptual
roles instead randiomly creating users
and groups

Like One top account create/set
polciies & service acconts only and the
other accounts apply it.

Unmanaged credentials night mare!
Key Management Services (KMS)

VPC network can be managed/deleted
as needed

Rootkits & Bootkits for VM hardening

Tools – AuditLogs, CSCC, KMS
Resource Hierarchy in general
Google Container Security
Infrastructure Security Software Supply Chain
Security
Run time Security
Cloud IAM, RBAC Google container Registry Stackdriver – monitoring,
Attack profiles
Compliance Certifications Security Vulnerability
Scanning
Anomolous detection by
third party products like
Twistlocks, acqua, sysdig
Cloud Audit Logging Secure base images Cloud SCC
Container Optimized
minimal OS, Node auto
upgrade
Regular builds Isolation
gVisor sandbox
Network policy, Private
clusters, Shared VPC
Deployment policies,
Binary authorization
Runtime detection – host,
network, workload, Boot
Google Kubernetes Engine Security
Managed Security by Google
●
Control plane security
– Google does the control plane management (Mater VM, Scheduler,
Cntroll manager, API server, etcd, CA, IAM, logging to stackdriver,) &
Patching the contol plane.
●
Node security
– Google handles K8s comoponents, COS (Chromium OS), logging &
monitoring. Autoupgarde & security patches automatically rolled out.
Manage base images.
– Live migration: Node auto upgrade is like adding new node and drain the
work from old.
● Workloads: User need to secure workloads. Protect the secret with
Cloud KMS or KMS plugin (Vault).
Hardening GKE
● Disable the Kubernetes web UI (Dashboard)
● Restrict Cluster discovery RBAC permission & binary authentication
● Restrict Traffic Among Pods with a Network Policy & Pod security policy
● Use Least Privilege Service Accounts for your Nodes
● Restrict your Node Service Account Scopes & Client Authentication Methods
● Protect node metadata & Automatically upgrade nodes
● Authorized networks & meta data concealment
● Google Container Registry (GCR) Vulnerability Scanning
● Third party container security.
● Read secuity bulletins – Vulnerabilties and solutiond
GKE Istio Security
Istio, a service mesh implementation, on GKE is an add-on.
●
The version of Istio installed is tied to the GKE version, and you will not be able to
update them independently.
●
Pilot:
●
Istio Auth ensures that services with sensitive data can only be accessed
●
Istio RBAC provides namespace-level, service-level, and method-level access control
●
Mixer:
●
Istio config policy on server side not client side.
●
Citadel:
●
MutualTLS authentication - both service-to-service and end-user-to-service
●
Automates key and certificate generation, distribution, rotation, and revocation.
Anthos Security
●
Single pane of glass
visibility across all clusters
●
Service-centric view of
your infrastructure
●
Configuration management
& Compliance centralized
●
Istio providing in-cluster
mTLS and certificate
management.
●
3rd
party marketplace
Hybrid cloud solutions: Anthos relies on Google
Kubernetes Engine (GKE) and GKE On-Prem to
manage Kubernetes installations in the environments
Google Cloud Partner Security
●
Splunk
●
Palo alto Networks
●
Checkpoint
●
F5
●
Brocade
●
Nginx
●
Symantec
●
Cisco
●
Hashicorp
●
Acqua
●
Blackduck
●
Twistlock
●
Stackrox
●
& more......
With 3rd
party providers, GCP Protects a wide
variety of hybrid cloud solutions and data.
References
●
https://cloud.google.com/containers/security/
●
https://cloud.google.com/kubernetes-engine/docs/security-bulletins
●
https://cloud.google.com/kubernetes-engine/docs/how-to/hardening-your-cluster
●
https://cloud.google.com/kubernetes-engine/docs/concepts/security-overview
●
https://cloud.withgoogle.com/next/19/sf/sessions?session=SEC110
●
https://console.cloud.google.com/security/command-center/welcome
●
https://cloud.google.com/security/partners/
●
https://cloud.google.com/anthos/docs/concepts/overview
●
https://cloud.google.com/istio/#security
●
https://youtu.be/PfXZovlblJc

More Related Content

What's hot (20)

PPTX
Csa container-security-in-aws-dw
Cloud Security Alliance, UK chapter
 
PDF
Kubecon seattle 2018 recap - Application Deployment aspects
Krishna-Kumar
 
PPTX
Kubernetes security with AWS
Kasun Madura Rathnayaka
 
PDF
Kubernetes - how to orchestrate containers
inovex GmbH
 
PDF
Extending Kubernetes
Johannes Rudolph
 
PDF
Introduction to kubernetes
Gabriel Carro
 
PDF
How Kubernetes helps Devops
Sreenivas Makam
 
PDF
Container Security Essentials
DNIF
 
PDF
Gentle introduction to containers and kubernetes
Nills Franssens
 
PDF
Kubernetes Multitenancy - KubeSec Enterprise Security Summit
Sanjeev Rampal
 
PDF
OpenStack 101 update
Kamesh Pemmaraju
 
PDF
Why kubernetes for Serverless (FaaS)
Krishna-Kumar
 
PPTX
Working with kubernetes
Nagaraj Shenoy
 
PDF
The Containers Ecosystem, the OpenStack Magnum Project, the Open Container In...
Daniel Krook
 
PDF
Kubernetes: https://youtu.be/KnjnQj-FvfQ
Rahul Malhotra
 
PPTX
Openstack architure part 1
Nhan Cao Thanh
 
PDF
Admission controllers - PSP, OPA, Kyverno and more!
SebastienSEYMARC
 
PDF
DockerCon EU 2015: Monitoring Docker
Docker, Inc.
 
PDF
Getting started with OpenStack
Knoldus Inc.
 
PDF
OpenStack Architecture
Mirantis
 
Csa container-security-in-aws-dw
Cloud Security Alliance, UK chapter
 
Kubecon seattle 2018 recap - Application Deployment aspects
Krishna-Kumar
 
Kubernetes security with AWS
Kasun Madura Rathnayaka
 
Kubernetes - how to orchestrate containers
inovex GmbH
 
Extending Kubernetes
Johannes Rudolph
 
Introduction to kubernetes
Gabriel Carro
 
How Kubernetes helps Devops
Sreenivas Makam
 
Container Security Essentials
DNIF
 
Gentle introduction to containers and kubernetes
Nills Franssens
 
Kubernetes Multitenancy - KubeSec Enterprise Security Summit
Sanjeev Rampal
 
OpenStack 101 update
Kamesh Pemmaraju
 
Why kubernetes for Serverless (FaaS)
Krishna-Kumar
 
Working with kubernetes
Nagaraj Shenoy
 
The Containers Ecosystem, the OpenStack Magnum Project, the Open Container In...
Daniel Krook
 
Kubernetes: https://youtu.be/KnjnQj-FvfQ
Rahul Malhotra
 
Openstack architure part 1
Nhan Cao Thanh
 
Admission controllers - PSP, OPA, Kyverno and more!
SebastienSEYMARC
 
DockerCon EU 2015: Monitoring Docker
Docker, Inc.
 
Getting started with OpenStack
Knoldus Inc.
 
OpenStack Architecture
Mirantis
 

Similar to Google Cloud Container Security Quick Overview (20)

PDF
Top 3 reasons why you should run your Enterprise workloads on GKE
Sreenivas Makam
 
PPTX
Anton Grishko "Multi-cloud with Google Anthos, Kubernetes and Istio. How to s...
Fwdays
 
PDF
Powerup & GCP | Workshop on Google Kubernetes Engine
Powerup
 
PDF
GCP Security Refresher and GKE Enterprise In Action
Stacy Véronneau
 
PDF
Implementing zero trust in IBM Cloud Pak for Integration
Kim Clark
 
PDF
Security threats with Kubernetes - Igor Khoroshchenko
Kuberton
 
PPTX
GCCP-Session 2
GDSCIIITDHARWAD
 
PPTX
Kubernetes best practices with GKE
GDG Cloud Bengaluru
 
PPTX
Hybrid - Seguridad en Contenedores v3.pptx
HansFarroCastillo1
 
PDF
Anthos Security: modernize your security posture for cloud native applications
Greg Castle
 
PPTX
Google Cloud Study Jam | GDSC NCU
Shivam254129
 
PDF
All Your Containers Are Belong To Us
Lacework
 
PDF
Hacking GCP For Fun by Agnibha Dutta.pdf
null - The Open Security Community
 
PDF
Stanislav Kolenkin & Igor Khoroshchenko - Knock Knock: Security threats with ...
NoNameCon
 
PDF
Skip the anxiety attack when building secure containerized apps
Haidee McMahon
 
PDF
Anthos Application Modernization Platform
GDG Cloud Bengaluru
 
PPTX
GCCP Session 2.pptx
DSCIITPatna
 
PPTX
Istio - A Service Mesh for Microservices as Scale
Ram Vennam
 
PPTX
CSJ4.pptx
GDSCAESB
 
PDF
Stop reinventing the wheel with Istio by Mete Atamel (Google)
Codemotion
 
Top 3 reasons why you should run your Enterprise workloads on GKE
Sreenivas Makam
 
Anton Grishko "Multi-cloud with Google Anthos, Kubernetes and Istio. How to s...
Fwdays
 
Powerup & GCP | Workshop on Google Kubernetes Engine
Powerup
 
GCP Security Refresher and GKE Enterprise In Action
Stacy Véronneau
 
Implementing zero trust in IBM Cloud Pak for Integration
Kim Clark
 
Security threats with Kubernetes - Igor Khoroshchenko
Kuberton
 
GCCP-Session 2
GDSCIIITDHARWAD
 
Kubernetes best practices with GKE
GDG Cloud Bengaluru
 
Hybrid - Seguridad en Contenedores v3.pptx
HansFarroCastillo1
 
Anthos Security: modernize your security posture for cloud native applications
Greg Castle
 
Google Cloud Study Jam | GDSC NCU
Shivam254129
 
All Your Containers Are Belong To Us
Lacework
 
Hacking GCP For Fun by Agnibha Dutta.pdf
null - The Open Security Community
 
Stanislav Kolenkin & Igor Khoroshchenko - Knock Knock: Security threats with ...
NoNameCon
 
Skip the anxiety attack when building secure containerized apps
Haidee McMahon
 
Anthos Application Modernization Platform
GDG Cloud Bengaluru
 
GCCP Session 2.pptx
DSCIITPatna
 
Istio - A Service Mesh for Microservices as Scale
Ram Vennam
 
CSJ4.pptx
GDSCAESB
 
Stop reinventing the wheel with Istio by Mete Atamel (Google)
Codemotion
 
Ad

More from Krishna-Kumar (20)

PDF
SODA Ambassadors & Community Ecosystem
Krishna-Kumar
 
PDF
Open Source Building Career and Competency
Krishna-Kumar
 
PDF
CCICI CIP 1.0 Testbed - Security access implementation and reference - v1.0
Krishna-Kumar
 
PDF
Google Anthos - Azure Stack - AWS Outposts :Comparison
Krishna-Kumar
 
PDF
Cloud Native Use Cases / Case Studies - KubeCon 2019 San Diego - RECAP
Krishna-Kumar
 
PDF
Cloud interoperability and open standards for digital india open infrasummit
Krishna-Kumar
 
PDF
Kubernetes Application Deployment with Helm - A beginner Guide!
Krishna-Kumar
 
PDF
KubeCon + CloudNativeCon Barcelona and Shanghai 2019 - Highlights
Krishna-Kumar
 
PDF
Introduction to ieee standards development - Bangalore Section
Krishna-Kumar
 
PDF
IEEE Standards Association - Introduction
Krishna-Kumar
 
PDF
IoTShow.in Bangalore 2019 - a Recap on 'IoT and Edge' Talk.
Krishna-Kumar
 
PPTX
Open Source Edge Computing Platforms - Overview
Krishna-Kumar
 
PDF
cncf overview and building edge computing using kubernetes
Krishna-Kumar
 
PDF
Evolution of containers to kubernetes
Krishna-Kumar
 
PDF
My Ladakh Marathon Run 2018
Krishna-Kumar
 
PDF
Now yoga - a study on where why what how
Krishna-Kumar
 
PPTX
CNCF Introduction - Feb 2018
Krishna-Kumar
 
PPTX
KubeCon USA 2017 brief Overview - from Kubernetes meetup Bangalore
Krishna-Kumar
 
PPTX
Yoga for confused IT engineer
Krishna-Kumar
 
PDF
Cloud, Big Data, IoT, ML - together to build a real world use case!
Krishna-Kumar
 
SODA Ambassadors & Community Ecosystem
Krishna-Kumar
 
Open Source Building Career and Competency
Krishna-Kumar
 
CCICI CIP 1.0 Testbed - Security access implementation and reference - v1.0
Krishna-Kumar
 
Google Anthos - Azure Stack - AWS Outposts :Comparison
Krishna-Kumar
 
Cloud Native Use Cases / Case Studies - KubeCon 2019 San Diego - RECAP
Krishna-Kumar
 
Cloud interoperability and open standards for digital india open infrasummit
Krishna-Kumar
 
Kubernetes Application Deployment with Helm - A beginner Guide!
Krishna-Kumar
 
KubeCon + CloudNativeCon Barcelona and Shanghai 2019 - Highlights
Krishna-Kumar
 
Introduction to ieee standards development - Bangalore Section
Krishna-Kumar
 
IEEE Standards Association - Introduction
Krishna-Kumar
 
IoTShow.in Bangalore 2019 - a Recap on 'IoT and Edge' Talk.
Krishna-Kumar
 
Open Source Edge Computing Platforms - Overview
Krishna-Kumar
 
cncf overview and building edge computing using kubernetes
Krishna-Kumar
 
Evolution of containers to kubernetes
Krishna-Kumar
 
My Ladakh Marathon Run 2018
Krishna-Kumar
 
Now yoga - a study on where why what how
Krishna-Kumar
 
CNCF Introduction - Feb 2018
Krishna-Kumar
 
KubeCon USA 2017 brief Overview - from Kubernetes meetup Bangalore
Krishna-Kumar
 
Yoga for confused IT engineer
Krishna-Kumar
 
Cloud, Big Data, IoT, ML - together to build a real world use case!
Krishna-Kumar
 
Ad

Recently uploaded (20)

PPTX
Chess King 25.0.0.2500 With Crack Full Free Download
cracked shares
 
PDF
Everything you need to know about pricing & licensing Microsoft 365 Copilot f...
Q-Advise
 
PPTX
How Can Reporting Tools Improve Marketing Performance.pptx
Varsha Nayak
 
PPTX
MiniTool Partition Wizard Crack 12.8 + Serial Key Download Latest [2025]
filmoracrack9001
 
PDF
Ready Layer One: Intro to the Model Context Protocol
mmckenna1
 
PDF
Message Level Status (MLS): The Instant Feedback Mechanism for UAE e-Invoicin...
Prachi Desai
 
PDF
Introduction to Apache Iceberg™ & Tableflow
Alluxio, Inc.
 
PPTX
PCC IT Forum 2025 - Legislative Technology Snapshot
Gareth Oakes
 
PPTX
TexSender Pro 8.9.1 Crack Full Version Download
cracked shares
 
PPTX
ChessBase 18.02 Crack + Serial Key Free Download
cracked shares
 
PDF
Instantiations Company Update (ESUG 2025)
ESUG
 
PDF
Australian Enterprises Need Project Service Automation
Navision India
 
PPTX
Operations Profile SPDX_Update_20250711_Example_05_03.pptx
Shane Coughlan
 
PDF
Best Insurance Compliance Software for Managing Regulations
Insurance Tech Services
 
PPTX
UI5con_2025_Accessibility_Ever_Evolving_
gerganakremenska1
 
PDF
chapter 5.pdf cyber security and Internet of things
PalakSharma980227
 
PPT
24-BuildingGUIs Complete Materials in Java.ppt
javidmiakhil63
 
PDF
How Attendance Management Software is Revolutionizing Education.pdf
Pikmykid
 
PDF
Optimizing Tiered Storage for Low-Latency Real-Time Analytics at AI Scale
Alluxio, Inc.
 
PDF
AI Software Engineering based on Multi-view Modeling and Engineering Patterns
Hironori Washizaki
 
Chess King 25.0.0.2500 With Crack Full Free Download
cracked shares
 
Everything you need to know about pricing & licensing Microsoft 365 Copilot f...
Q-Advise
 
How Can Reporting Tools Improve Marketing Performance.pptx
Varsha Nayak
 
MiniTool Partition Wizard Crack 12.8 + Serial Key Download Latest [2025]
filmoracrack9001
 
Ready Layer One: Intro to the Model Context Protocol
mmckenna1
 
Message Level Status (MLS): The Instant Feedback Mechanism for UAE e-Invoicin...
Prachi Desai
 
Introduction to Apache Iceberg™ & Tableflow
Alluxio, Inc.
 
PCC IT Forum 2025 - Legislative Technology Snapshot
Gareth Oakes
 
TexSender Pro 8.9.1 Crack Full Version Download
cracked shares
 
ChessBase 18.02 Crack + Serial Key Free Download
cracked shares
 
Instantiations Company Update (ESUG 2025)
ESUG
 
Australian Enterprises Need Project Service Automation
Navision India
 
Operations Profile SPDX_Update_20250711_Example_05_03.pptx
Shane Coughlan
 
Best Insurance Compliance Software for Managing Regulations
Insurance Tech Services
 
UI5con_2025_Accessibility_Ever_Evolving_
gerganakremenska1
 
chapter 5.pdf cyber security and Internet of things
PalakSharma980227
 
24-BuildingGUIs Complete Materials in Java.ppt
javidmiakhil63
 
How Attendance Management Software is Revolutionizing Education.pdf
Pikmykid
 
Optimizing Tiered Storage for Low-Latency Real-Time Analytics at AI Scale
Alluxio, Inc.
 
AI Software Engineering based on Multi-view Modeling and Engineering Patterns
Hironori Washizaki
 

Google Cloud Container Security Quick Overview