Secure your containerised workloads depends significantly on steps to be done prior to deployment: vulnerability scans of your images, generation and storing of SBOMs, among many others.
There is also the other side of ensuring security of your runtime workloads, detecting and alerting on unpredictable workloads being launched from containers (such as shells or unexpected processes inside the containers), attempts to access unexpected remote endpoints, or attempts to install additional tools to the containers - including pip or other packages.
This session will describe the proposed integration in our CERN Kubernetes service to automated the process of setting up these addons in your clusters as well as automating alerts.
Recording: YouTube