cncf / tag-security

🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!
https://cncf.io/projects
Other
1.99k stars 497 forks source link

[Unconference] Seccomp policy usage: why there is no adoption? #1134

Closed slashben closed 7 months ago

slashben commented 8 months ago

Description: Discussion about Seccomp policies, why they're useful and what are the reason they don't have wide adoption in the ecosystem. Benefits to Ecosystem: Seccomp is one of the best ways to limit blast radius of container exploits. It can protect the kernel from malicious actors executing in containers and it also limits what an attacker can do within the container. Despite the support Kubernetes has for Seccomp profiles, the adoption is very low. Have high adoption would raise the security level considerably.

mlieberman85 commented 8 months ago

Thanks for your submission @slashben. The submission has been accepted and scheduled for Thursday 11/09 at 2:55PM-3:30PM. Congrats!

mnm678 commented 7 months ago

Thanks for the presentation! Closing as completed.