Cloud Security Podcast

Scaling Container Security Without Slowing Developers

12 snips
Apr 17, 2025
Cailyn Edwards, Co-Chair of Kubernetes SIG Security and Senior Security Engineer at Auth0 by Okta, shares her expertise on scaling container security. She discusses the importance of automating security and bridging the gap between security teams and developers for better collaboration. The conversation highlights the 'Shift Down' philosophy, leveraging open-source tools, and the significance of minimal, immutable images for security. Cailyn also emphasizes getting leadership buy-in to align security with business goals and shares personal anecdotes that enrich the discussion.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Widespread Kubernetes Security Risks

  • Many Kubernetes deployments have thousands to millions of exposed insecure ports and default configurations.
  • This widespread issue arises from a lack of awareness about risks in container default setups and configurations.
ADVICE

Automate Container Vulnerability Scanning

  • Start manual security checks by reviewing Dockerfiles for common issues and use tools like Trivy for deeper vulnerability scans.
  • Automate scans in pipelines to catch vulnerabilities early and integrate alerts for immediate action.
ADVICE

Use Immutable Base Images

  • Provide developers with secure, immutable base images like ChainGuard or BottleRocket to prevent ad-hoc changes.
  • Integrate continuous scanning in CI/CD pipelines and production to detect and patch vulnerabilities promptly.
Get the Snipd Podcast app to discover more snips from this episode
Get the app