|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/mastering-kubernetes-api-security-and-network-policies/
课程评论:没有评论
课程名称:掌握Kubernetes API安全性与网络策略 课程概述: Kubernetes是现代云原生应用的基础,但确保其API和网络通信的安全至关重要。在本课程中,您将学习如何保护Kubernetes环境免受未经授权的访问,执行安全策略,并确保服务之间的加密通信。 课程内容: 1. Kubernetes集群架构 - 理解Kubernetes架构及示例 - 工作节点的角色 - 控制平面组件(主节点) - API服务器、Etcd、调度器、控制器管理器、Kubelet、服务代理、POD(Pod)、容器引擎(Docker、Containerd或Rocket) 2. Kubernetes API访问的RBAC策略 - 介绍和核心组件 - RBAC在Kubernetes API访问中的工作原理 - 角色与角色绑定的协同工作 - 定义权限和访问的Kubernetes角色 - 创建角色并将角色绑定到用户或服务帐户 - 实验:在Kubernetes中实施RBAC 3. 客户端认证使用SSL/TLS证书 - 客户端证书生成概述 - 生成私钥和证书签署请求(CSR) - 用Minikube的CA签署CSR生成用户证书 - 在Kubernetes配置中设置客户端凭证 - 验证用户凭证 4. 扩展RBAC权限管理命名空间中的Pod - 生成私钥和CSR - 签署CSR生成用户证书 - RBAC角色权限创建、验证及测试 5. 实施和测试Pod通信的网络策略 - 介绍Kubernetes网络策略 - 理解Pod间通信限制 - 实验:通过网络策略强制Pod间限制 6. 在Kubernetes中安全部署和访问Nginx - 通过HTTPS保护Nginx概述 - 部署Nginx Pod并公开至外部流量 - 安全设置Nginx服务器及生成自签名TLS证书 本课程将通过实践操作和实验,使学员深入理解Kubernetes API安全性和网络策略的实施,从而提升云原生应用的安全性。
Kubernetes is the backbone of modern cloud-native applications, but securing its API and network communication is critical. In this course, you will learn how to protect your Kubernetes environment from unauthorized access, enforce security policies, and ensure encrypted communication between services.Course ContentArchitecture of the Kubernetes ClusterUnderstanding the Kubernetes architecture with examplesWorking with KubernetesRoles of the Master NodeComponents of the Control Plane (Master Node)API ServerEtcdSchedulerController ManagerKubeletService ProxyPOD (Pod)Container Engine (Docker, Containerd, or Rocket)RBAC Policies for Securing Kubernetes API AccessIntroductionKey components of RBACHow RBAC works in Kubernetes API Access?How Role and RoleBinding Work TogetherKubernetes Roles: Defining Permissions and AccessPermissions Granted by Kubernetes RolesCreate a roleBind the Role to a User or Service AccountHands-On Lab: Implementing RBAC in KubernetesIntroduction to Scenario-Based RBAC ExercisesSet Up a VM for a Minikube ClusterSet Up a K8s Minikube Cluster - Part 1Set Up a K8s Minikube Cluster - Part 2Set Up a K8s Minikube Cluster - Part 3Start the K8s Minikube ClusterCreate a Namespace and Run a PodClient Authentication using SSL/TLS CertificatesOverview of Client Certificate GenerationGenerate a Private KeyGenerate a Certificate Signing Request (CSR)Sign a CSR with Minikube's CA to Generate a User CertificateSet Client Credentials in Kubernetes ConfigVerify User Credentials in Kubernetes ConfigRBAC: Role and RoleBindingCreate a RoleVerify the Role and Its Associated PermissionsCreate a RoleBinding to Assign a UserTest RBAC PermissionsExpand RBAC Permissions to Manage Pods in a NamespaceGenerate a Private Key and CSRGenerate a User Certificate by Signing CSR with Minikube CASet User Credentials in Kubernetes (K8s)Create a Role with Specific PermissionsCreate a RoleBindingRBAC Testing: Validate PermissionsAccess the K8s Minikube Cluster as a UserList and Manage Kubernetes ContextsSet Up a Kubernetes Context for a UserVerify RBAC Permissions in a New ContextSet Up a K8s Context for a Different UserTest RBAC Permissions for Pod CreationModify RBAC Role Permissions in K8sImplement and Test Network Policies for Pod CommunicationIntroduction to Kubernetes Network PoliciesWhy Restrict Pod-To-Pod Communication?Understanding K8s Network Policies and CNI PluginsExample Use Case ScenariosHands-On Lab: Enforcing Pod-to-Pod Restrictions with Network PoliciesSet Up a VM for a Kubernetes ClusterStart Minikube with Cilium CNIDeploy Two Pods and Assign LabelsTest Pod-to-Pod Connectivity with CurlCreate a Network Policy to Restrict Pod CommunicationVerify Pod-to-Pod Connectivity is BlockedNetwork Policy to Restrict Ingress and Egress TrafficConfiguring Network Policy for Selective Pod CommunicationOverview of Selective Pod CommunicationNetwork Policy for Selective Pod CommunicationTest Pod ConnectivityDeploy a Pod and Verify Its Network ConnectivitySecuring, Deploying, and Accessing Nginx in KubernetesOverview of Securing Nginx with HTTPSDeploy and Expose a Nginx Pod to External TrafficAccess Nginx Web Server Through HTTPSet Up Nginx on Host Machine for Accessing Nginx PodAccess Nginx Web Server via Web Browser (HTTP Only)Secure Nginx Server with HTTPS (TLS) on K8s ClusterDeploy and Expose a Nginx Pod to External TrafficGenerate a self-signed TLS CertificateStore the TLS Certificate as a SecretCheck Minikube's Ingress Controller StatusCreate Ingress Resource for HTTPSLast lecture