In this episode of The ./havoc Podcast Cybersecurity Research series, Andrew Martin, co-author of Hacking Kubernetes (O'Reilly Media, Inc. ISBN: 9781492081739) provides an in-depth look into how his experience advising clients on securing production Kubernetes clusters resulted in a comprehensive and masterfully written book that any CISO, Security Engineer or Incident Responder responsible for securing and monitoring Kubernetes should not go without.
Hacking Kubernetes book - https://www.oreilly.com/library/view/hacking-kubernetes/9781492081722/, https://www.amazon.com/Hacking-Kubernetes-Threat-Driven-Analysis-Defense/dp/1492081736
OpenUK - https://openuk.uk/
OpenSSF - https://openssf.org/
The Linux Programming Interface - https://nostarch.com/tlpi
Andrew has an incisive security engineering ethos gained building and destroying high-traffic web applications. Proficient in systems development, testing, and operations, he is comfortable profiling and securing every tier of a bare metal or cloud native system, and has battle-hardened experience delivering containerised solutions to enterprise and government. He is a co-founder at ControlPlane (https://control-plane.io/). Andrew has presented at international conferences including KubeCon, Velocity, SANS, OWASP, DevOpsDays, Container Camp, IPExpo, and numerous other local events and meetups.
Video recording: https://youtu.be/6o9gpB5sCqM