Container Security

I have written a blog post on developing validations for Kubernetes CRDS with CEL & kubebuilder marker comments. This feature is still in beta phase & got introduced couple of weeks ago in Kubernetes 1.25. Please have a look & let me know your thoughts!

TODO Check out this threat model for a serverless platform. Attackers execute stuff in our sandbox, but:

  • you get 10ms CPU
  • you’re in a v8 isolate sandbox
  • you have layer 7 restrictions
  • and if you smell salty, you get rescheduled to a confined VM

Face throwing a kissOk hand