Kubernetes Podcast from Google cover image

Kubernetes Podcast from Google

Container Security, with Michele Chubrika

Oct 15, 2024
Michele Chubrika, a Cloud Security Developer Advocate at Google, joins Anton Chuvakin for a deep dive into container security. They debunk myths about isolation and discuss the intricacies between virtual machines and containers, emphasizing trust boundaries within Kubernetes. The conversation highlights the importance of proactive security practices and the potential of WebAssembly to reduce attack surfaces. They also tackle developer challenges in containerized environments, sharing insights on dependency management and the evolving landscape of cloud-native security.
55:49

Podcast summary created with Snipd AI

Quick takeaways

  • Security in containers and VMs relies on organizational architecture and collaboration between security and platform engineering teams rather than the technology itself.
  • Properly understanding isolation versus segregation in containers is crucial for implementing effective security measures within Kubernetes clusters.

Deep dives

VMs vs. Containers: A Complex Security Debate

The discussion begins with the common debate of whether virtual machines (VMs) or containers are more secure, which is framed as a misguided question. Security expert Michelle Shubirka emphasizes that the security of either technology heavily depends on the organization’s architecture and collaboration between security and platform engineering teams. She points out that containers operate under a shared kernel, which lacks true isolation, and thus security practices must adjust accordingly. The interplay of cultural factors within teams and their willingness to innovate further influences whether containers or VMs achieve higher security levels.

Remember Everything You Learn from Podcasts

Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.
App store bannerPlay store banner