Book Image

Cloud Native with Kubernetes

By : Alexander Raul
Book Image

Cloud Native with Kubernetes

By: Alexander Raul

Overview of this book

Kubernetes is a modern cloud native container orchestration tool and one of the most popular open source projects worldwide. In addition to the technology being powerful and highly flexible, Kubernetes engineers are in high demand across the industry. This book is a comprehensive guide to deploying, securing, and operating modern cloud native applications on Kubernetes. From the fundamentals to Kubernetes best practices, the book covers essential aspects of configuring applications. You’ll even explore real-world techniques for running clusters in production, tips for setting up observability for cluster resources, and valuable troubleshooting techniques. Finally, you’ll learn how to extend and customize Kubernetes, as well as gaining tips for deploying service meshes, serverless tooling, and more on your cluster. By the end of this Kubernetes book, you’ll be equipped with the tools you need to confidently run and extend modern applications on Kubernetes.
Table of Contents (22 chapters)
1
Section 1: Setting Up Kubernetes
5
Section 2: Configuring and Deploying Applications on Kubernetes
11
Section 3: Running Kubernetes in Production
16
Section 4: Extending Kubernetes

Handling intrusion detection, runtime security, and compliance on Kubernetes

Once you have set your Pod security policies and network policies – and generally ensured that your configuration is as watertight as possible – there are still many attack vectors that are possible in Kubernetes. In this section, we will focus on attacks from within a Kubernetes cluster. Even with highly specific Pod security policies in place (which definitely do help, to be clear), it is possible for containers and applications running in your cluster to perform unexpected or malicious operations.

In order to solve this problem, many professionals look to runtime security tools, which allow constant monitoring and alerting of application processes. For Kubernetes, a popular open source tool that can accomplish this is Falco.

Installing Falco

Falco bills itself as a behavioral activity monitor for processes on Kubernetes. It can monitor both your containerized applications running...