Implementing DevSecOps with Docker and Kubernetes. An Experiential Guide to Operate in the DevOps Environment for Securing and Monitoring Container Applications
Book information
Description
Cover Page Title Page Copyright Page Dedication Page About the Author About the Reviewers Acknowledgements Preface Errata Table of Contents 1. Getting Started with DevSecOps Structure Objectives From DevOps to DevSecOps Getting started with DevSecOps Advantages of implementing DevSecOps DevSecOps lifecycle ShiftLeft security DevSecOps methodologies Applying the DevSecOps methodology Security testing Security code review Continuous integration and continuous delivery Continuous Integration (CI) Orchestrating CI Selection of continuous integration tools Continuous delivery (CD) - Pipelines in software development Advantages of continuous delivery Continuous Integration (CI) versus Continuous Delivery (CD) DevSecOps tools Static Analysis Security Testing (SAST) Dynamic Analysis Security Testing (DAST) Dependency analysis Infrastructure as Code security Secrets management Vulnerability management Vulnerability assessment Alerts and monitoring Conclusion Points to remember Multiple choice questions Answers Questions Key terms 2. Container Platforms Structure Objective Docker containers What is Docker? Containers versus virtual machines Docker features for container management Docker architecture Docker engine Docker client Containerd Podman Podman design and main functions Podman commands Container orchestration Docker compose Kubernetes Kubernetes architecture Kubernetes key terms Kubernetes cloud provider solutions Kubernetes alternatives Docker Swarm Nomad Rancher - Kubernetes as a service Conclusion Points to remember Multiple choice questions Answers Questions Key terms 3. Managing Containers and Docker Images Introduction Structure Objectives Managing Docker images Introducing Docker images Docker layers Image tags Design considerations for Docker Images Dockerfile commands What is a Dockerfile? Building images from Dockerfile Best practices writing DockerFiles Managing Docker containers Searching and executing a Docker image Executing a container in background mode Inspecting Docker containers Optimizing Docker images Docker’s cache Building an application with NodeJS Reducing image size with multistage Reducing image size with alpine Linux Distroless Docker images Conclusion Points to remember Multiple choice questions Answers Questions Key terms 4. Getting Started with Docker Security Introduction Structure Objectives Docker security principles and best practices Docker daemon attack surface Security best practices Execution with non-root user Start containers in read-only mode Disable the setuid and setgid permissions Verifying images with Docker Content Trust Resource limitation Docker capabilities Listing all capabilities Add and drop capabilities Disabling ping command in a container Adding capability for managing network Execution of privileged containers Docker Content Trust Notary as a tool for managing images Docker Registry What is a registry? Public Docker registries Creating Docker registry Quay.io image repository Harbor repository Conclusion Points to remember Multiple choice questions Answers Questions Key terms 5. Docker Host Security Structure Objectives Docker daemon security Auditing files and directories Kernel Linux security and SELinux Apparmor and Seccomp profiles Installing AppArmor on Ubuntu distributions AppArmor Docker-default profile Run container without AppArmor profile Run container with Seccomp profile Deny all syscalls Run a container with no seccomp profile Write a seccomp profile Security in-depth Reducing the container attack surface Docker bench security Docker bench security execution Auditing Docker host with Lynis Conclusion Points to remember Multiple choice questions Answers Questions Key terms 6. Docker Images Security Structure Objectives Docker Hub repository and security scanning process Docker security scanning Docker security scanning process Open source tools for vulnerability analysis Clair security scanning Dagda OWASP dependency check Trivy Scanning Docker images with Clair and Quay Quay.io image repository Analyzing Docker images with Anchore Deploying Anchore engine Policies for image evaluation Conclusion Points to remember Multiple choice questions Answers Questions Key terms 7. Auditing and Analyzing Vulnerabilities in Docker Containers Structure Objectives Docker containers threats and attacks Dirty Cow Exploit (CVE-2016-5195) Preventing DirtyCow exploit with apparmor Vulnerability jack in the box (CVE-2018-8115) Most vulnerable packages Analyzing vulnerabilities in Docker images Security vulnerability classification Alpine image vulnerability (CVE-2019-5021) CVE in Docker images Getting CVE details with Vulners API Conclusion Points to remember Multiple choice questions Answers Questions Key terms 8. Managing Docker Secrets and Networking Structure Objectives Introducing container secrets What is a secret? Managing secrets in Docker Docker secrets with Docker swarm scenario Introducing container networking Bridge mode Host mode Network managing in Docker Docker networking Containers communication and port mapping Configuring port forwarding between containers and Docker host Creating and managing Docker networks Docker network commands Creating a network Connecting a container to a network Linking containers Conclusion Points to remember Multiple choice questions Answers Questions Key terms 9. Docker Container Monitoring Structure Objectives Container statistics, metrics, and events Log management Containers stats Obtain metrics using docker inspect Events in Docker containers Other Docker container monitoring tools Performance monitoring with cAdvisor Performance monitoring with Dive Container monitoring with Falco Launching Falco container Falco rules Nginx container monitoring Conclusion Points to remember Multiple choice questions Answers Questions Key terms 10. Docker Container Administration Structure Objectives Introducing container administration Container administration with Portainer Deploying Portainer in Docker Swarm Cluster Docker Swarm Administration with Portainer Container administration with Rancher Deploying Kubernetes using Rancher Container administration with OpenShift Conclusion Points to remember Multiple choice questions Answers Questions Key terms 11. Kubernetes Architecture Structure Objectives Kubernetes architecture Components of a Kubernetes cluster Kubernetes objects Pods Volumes Deployment ReplicaSet Services StatefulSets Kubernetes networking model Container to container communication within Pods Pod to Pod communication through cluster nodes External communication from the Pod Tools for deploying Kubernetes Cluster election Working with Kubernetes using Minikube Interacting with the cluster using kubectl Conclusion Points to remember Multiple choice questions Answers Questions Key terms 12. Kubernetes Security Structure Objectives Introducing Kubernetes security Configuring Kubernetes Kubernetes security best practices Using secrets Firewall ports Restrict the Docker pull command API authorization and anonymous authentication Management of resources and limits Security features built into k8s Managing secrets Kubernetes secrets Other projects for managing Kubernetes secrets Handle security risks in Kubernetes Analyzing Kubernetes components security Pod security policies Static analysis with kube-score Auditing the state of the cluster Using livenessProbe and readinessProbe Setting limits and resource requests Applying affinity rules between nodes and pods Conclusion Points to remember Multiple choice questions Answers Questions Key terms 13. Auditing and Analyzing Vulnerabilities in Kubernetes Structure Objectives KubeBench security CIS benchmarks for Kubernetes with KubeBench Kubernetes security projects Kube-hunter Kubesec Kubectl plugins for managing Kubernetes kubectl-trace Kubectl-debug Ksniff kubectl-dig Rakkess Kubestriker Other tools Analyzing Kubernetes vulnerabilities and CVEs Kubernetes vulnerabilities Vulnerability with PodSecurityPolicy Vulnerability in the use of certificates Conclusion Points to remember Multiple choice questions Answers Questions Key terms 14. Observability and Monitoring in Kubernetes Structure Objectives Introducing observability and monitoring Observability in a Kubernetes cluster Cluster monitoring Kubernetes dashboard Other Kubernetes Dashboards Enhancing observability and monitoring with Prometheus and Grafana Prometheus Prometheus architecture Prometheus installation Collecting metrics Exploring metrics with Grafana Other tools Conclusion Points to remember Multiple choice questions Answers Questions Key terms Index
Similar books
MySQL® Notes for Professionals book
2018 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36
2010 · PDF
THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.
1858 · PDF
Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.
2022 · PDF
The travels of Capts. Lewis and Clarke from St. Louis, by way of the Missouri and Columbia rivers, to the Pacific ocean; performed in the years 1804, 1805 & 1806, by order of the government of the United States. Containing delineations of the manners, customs, religion, &c. of the Indians, comp. from various authentic sources, and original documents, and a summary of the Statistical view of the Indian nations, from the official communication of Meriwether Lewis. Illustrated with a map of the country, inhabited by the western tribes of Indians
1809 · PDF
Professional Linux kernel architecture ''Wrox programmer to programmer''--Cover. - ''What you are reading right now is the result of an evolution over more than seven years: After two years of writing, the first edition was published in German by Carl Hanser Verlag in 2003. It then described kernel 2.6.0. The test was used as a basis for the low-level design documentation for the EAL4+ security evaluation of Red Hat Enterprise Linux 5, requiring to update it to kernel 2.6.18 (if the EAL acronym does not mean anything to you, then Wikipedia is once more your friend). Hewlett-Packard sponsored the translation into English and has, thankfully, granted the rights to publish the result. Updates to kernel 2.6.24 were then performed specifically for this book''--P. ix
2008 · PDF