Orchestrating Least Privilege - Diogo Mónica (Docker) @ContainerCamp
Orchestrating Least Privilege - Diogo Mónica (Docker)  @ContainerCamp
Uploaded September 2017 | Updated September 2026, 5 days ago
The popularity of containers has driven the need for distributed systems that have the ability to manage resources, place workloads and adapt to faults. These so-called Container Orchestrators have seen a rise in popularity in the enterprise that is reminiscent of the early container adoption. Open-source projects such as Docker Swarm, Kubernetes and Marathon make it easy for anyone to manage their container workloads using their cloud-based or on-premise infrastructure. Unfortunately, a lot of these orchestrator systems have not been architected with security in mind. In particular, compromise of a less-privileged node usually allows an attacker to escalate privileges to either gain control of the whole system, or to access resources it shouldn't have access to. Given the popularity of containers in the enterprise, it is critical that we start designing orchestrators that are designed with security in mind, and follow the principle of least-privilege, where any participant of the system only has access to the resources that are strictly necessary for its legitimate purpose. No more, no less.

About Diogo: Diogo Mónica is the security lead at Docker, an open platform for building, shipping and running distributed applications. He was an early employee at Square where he led the platform security team, has a BSc, MSc and PhD degrees in Computer Science, serves on the board of advisors of several security startups, and is a long-time IEEE Volunteer.

Container Camp is the community conference about software containers and is Australia's first conference dedicated to container technology.

Captured on 22-24 May, 2017 at the SMC Centre. Sydney, Australia
Orchestrating Least Privilege - Diogo Mónica (Docker)Lessons learnt while operating multi-tenant kubernetes cluster in production - Prateek Nayak (MYOB)Building geographically distributed microservices with containers - Jussi Nummelin (Kontena Inc.)Istio 1.0: time for production! - Craig Box (Google)OCI and Open Container Standards - Jonathan Boulle (NStack)Going crazy with Docker multi-stage build - Jorge Arteiro (IBM)Whats new in Docker? - Mano MarksYour (container) secrets safe with me - Liz Rice (Aqua Security)An introduction to LXD, the container lighter-visor - Stéphane GraberJohn Daniels: Pets, Cattle and Cloned SheepDeploying Serverless on Kubernetes w/ Funktion, Iron Functions & Fission  - Vishal BiyaniDon’t be a fail whale, secure your containers - Sarah Young (Versent)
Container Camp |

Orchestrating Least Privilege - Diogo Mónica (Docker)

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER