Cloud Native platforms such as Kubernetes help developers to easily get started deploying and running their applications at scale. But as developers push out updates at a faster rate, and as the barrier between dev, ops, and sec gets blurrier, how you secure and maintain compliance standards in these environments becomes extremely important. To answer this question we’ll describe an end-to-end security stack, built only with open source components. We will cover the entire process, starting with approaches to do image scanning inside your continuous integration process. Then we’ll talk about runtime security and finally forensics, with a focus on volatile containers that are frequently started, migrated, and updated in an orchestrated environment like Kubernetes. Here we’ll dig into tools like Anchore, CoreOS Clair, and Sysdig Falco. Attendees will walk away with a good understanding of the challenges of securing a Cloud Native platform and practical advice on using open source tools as part of their security strategy.