My Account Log in

2 options

Kubernetes Secrets Handbook : Design, Implement, and Maintain Production-Grade Kubernetes Secrets Management Solutions / Emmanouil Gkatziouras [and three others].

EBSCOhost Academic eBook Collection (North America) Available online

View online

O'Reilly Online Learning: Academic/Public Library Edition Available online

View online
Format:
Book
Author/Creator:
Gkatziouras, Emmanouil, author.
Language:
English
Subjects (All):
Kubernetes.
Application software--Development--Computer programs.
Application software.
Physical Description:
1 online resource (294 pages) : illustrations
Edition:
First edition.
Place of Publication:
Birmingham, England : Packt Publishing, [2024]
Biography/History:
Gkatziouras Emmanouil: Emmanouil Gkatziouras started his career in software as a Java developer. Since 2015, he has worked daily with cloud providers such as GCP, AWS and Azure, and container orchestration tools such as Kubernetes. He has fulfilled many roles, either in lead positions or as an individual contributor. He enjoys being a versatile engineer and collaborating with development, platform, and architecture teams. He loves to give back to the developer community by contributing to open-source projects and by blogging on various software topics. He is committed to continuous learning and is a holder of certifications such as CKA, CCDAK, PSM, CKAD, and PSO. He is the author of A Developer's Essential Guide to Docker Compose'. Adams Rom: Rom Adams (ne Romuald Vandepoel) is an open-source and C-Suite advisor with 20 years of experience in the IT industry. He is a cloud-native expert who helps organizations to modernize and transform with open-source solutions. He is advising companies and lawmakers on their open- and inner-source strategies. Previously, a Principal Architect at Ondat, a cloud-native storage company acquired by Akamai, where he designed products and hybrid cloud solutions and held roles at Tyco, NetApp, and Red Hat becoming a subject matter expert in hybrid cloud. He was moderator and speaker for several events, sharing his insights on culture, process, technology adoption, and passion about open innovation. Xi Chen: Chen Xi is a highly skilled Uber Platform Engineer. As a Tech Leader, he contributed to the Secret and Key Management Platform service, leading and delivering secrets as a service with a 99. 99% SLA for thousands of Uber container services across hybrid environments. His cloud infrastructure prowess is evident from his work on Google Kubernetes Engine (GKE) and the integration of Spire-based PKI systems. Prior to joining Uber, he worked at VMware, where he developed microservices for VMware's Hybrid Kubernetes management platform (Tanzu Mission Control) and VMware Kubernetes Engine for multi-cloud (Cloud PKS). Chen is also a contributing author to the Certified Kubernetes Security Specialist (CKS) exam.
Summary:
Gain hands-on skills in Kubernetes Secrets management, ensuring a comprehensive overview of the Secrets lifecycle and prioritizing adherence to regulatory standards and business sustainability Key Features Master Secrets encryption, encompassing complex life cycles, key rotation, access control, backup, and recovery Build your skills to audit Secrets consumption, troubleshoot, and optimize for efficiency and compliance Learn how to manage Secrets through real-world cases, strengthening your applications' security posture Purchase of the print or Kindle book includes a free PDF eBook Book Description Securing Secrets in containerized apps poses a significant challenge for Kubernetes IT professionals. This book tackles the critical task of safeguarding sensitive data, addressing the limitations of Kubernetes encryption, and establishing a robust Secrets management system for heightened security for Kubernetes. Starting with the fundamental Kubernetes architecture principles and how they apply to the design of Secrets management, this book delves into advanced Kubernetes concepts such as hands-on security, compliance, risk mitigation, disaster recovery, and backup strategies. With the help of practical, real-world guidance, you'll learn how to mitigate risks and establish robust Secrets management as you explore different types of external secret stores, configure them in Kubernetes, and integrate them with existing Secrets management solutions. Further, you'll design, implement, and operate a secure method of managing sensitive payload by leveraging real use cases in an iterative process to enhance skills, practices, and analytical thinking, progressively strengthening the security posture with each solution. By the end of this book, you'll have a rock-solid Secrets management solution to run your business-critical applications in a hybrid multi-cloud scenario, addressing operational risks, compliance, and controls. What you will learn Explore Kubernetes Secrets, related API objects, and CRUD operations Understand the Kubernetes Secrets limitations, attack vectors, and mitigation strategies Explore encryption at rest and external secret stores Build and operate a production-grade solution with a focus on business continuity Integrate a Secrets Management solution in your CI/CD pipelines Conduct continuous assessments of the risks and vulnerabilities for each solution Draw insights from use cases implemented by large organizations Gain an overview of the latest and upcoming Secrets management trends Who this book is for This handbook is a comprehensive reference for IT professionals to design, implement, operate, and audit Secrets in applications and platforms running on Kubernetes. For developer, platform, and security teams experienced with containers, this Secrets management guide offers a progressive path--from foundations to implementation--with a security-first mindset. You'll also find this book useful if you work with hybrid multi-cloud Kubernetes platforms for organizations concerned with governance and compliance requirements.
Contents:
Intro
Title Page
Copyright and Credits
Dedicated
Foreword
Contributors
Table of Contents
Preface
Part 1: Introduction to Kubernetes Secrets Management
Chapter 1: Understanding Kubernetes Secrets Management
Technical requirements
Understanding Kubernetes' origins and design principles
From bare metal to containers
Kubernetes overview
Kubernetes design principles
Kubernetes architecture
Getting hands-on
from a local container to a Kubernetes Pod
Secrets within Kubernetes
Secrets concepts
Storing Secrets on Kubernetes
Why should we care?
Security exposures
Summary
Chapter 2: Walking through Kubernetes Secrets Management Concepts
What are Kubernetes Secrets, and how do they differ from other Kubernetes objects?
Different types of Secrets and their usage scenarios
Opaque
Kubernetes service account token
Docker config
Basic authentication
TLS client or server
Token data
Conclusion
Creating, modifying, and deleting Secrets in Kubernetes
data and stringData
Updating Secrets
Deleting Secrets
Conclusion
Kubernetes Secrets configuration in different deployment scenarios
Secret usage among environments
From development to deployment
Requirement for managing Secrets, including secure storage and access control
Secure storage
Access control
Git and encryption
Securing access to Secrets with RBAC
RBAC introduction
RBAC and Secrets
Auditing and monitoring secret usage
minikube note
Chapter 3: Encrypting Secrets the Kubernetes-Native Way
Kubernetes-native encryption
Standalone native encryption
Native encryption with an external component
Going further with securing etcd
Linux system hardening
Linux data encryption
Transport
Chapter 4: Debugging and Troubleshooting Kubernetes Secrets
Discussion of common issues with Kubernetes Secrets
Helm and Helm Secrets
Secret application pitfalls
Debugging and troubleshooting Secrets
The describe command
Non-existing Secrets
Badly configured Secrets
Troubleshooting and observability solutions
Best practices for debugging and troubleshooting Secrets
Avoiding leaking Secrets
Part 2: Advanced Topics
Kubernetes Secrets in a Production Environment
Chapter 5: Security, Auditing, and Compliance
Cybersecurity versus cyber risk
Cybersecurity
Cyber risk
Compliance standards
Adopting a DevSecOps mindset
Tools
Trivy
kube-bench
Compliance Operator
StackRox
Kubernetes logging
Chapter 6: Disaster Recovery and Backups
Technical requirements
Notes:
Includes index.
Description based on print version record.
ISBN:
9781805127154
1805127152
OCLC:
1420910391

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account