State of Least Privilege Container

No ratings

Presented at INFOSEK 2020 by

There are many publications on the security of container runtimes and their isolation capabilities, many of which cover capabilities by the executed containers. In this talk, I will describe existing approaches to footprint containers to determine the capabilities they actually require to successfully run. The resulting insights can be used to integrate tooling into your CI systems to determine required capabilities during building and testing and then restricting containers during runtime to that exact set.