<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Tim Allclair</title><link>/</link><description>Recent content on Tim Allclair</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Tue, 19 Nov 2019 00:00:00 +0000</lastBuildDate><atom:link href="/index.xml" rel="self" type="application/rss+xml"/><item><title>Walls Within Walls</title><link>/talks/20191119-walls-within-walls/</link><pubDate>Tue, 19 Nov 2019 00:00:00 +0000</pubDate><guid>/talks/20191119-walls-within-walls/</guid><description>What happens if an attacker escapes a container and compromises your node? Is it game over for the whole cluster, or can you limit the blast radius? Whether it be for defense in depth or multi-tenancy, it is important to understand the security boundaries in your cluster. In this talk, we’ll discuss various isolation approaches and evaluate them through the eyes of an attacker who has compromised a node and is looking to propagate.</description></item><item><title>State of Kubernetes Security</title><link>/talks/20191118-state-of-security/</link><pubDate>Mon, 18 Nov 2019 00:00:00 +0000</pubDate><guid>/talks/20191118-state-of-security/</guid><description>Last year we presented on the state of Kubernetes Security across the past, present, and future. This year, we&amp;rsquo;ll continue that tradition by:
Reviewing the major security vulnerabilities and milestones of 2019 Reviewing progress on the Big Problems we highlighted in 2018, and highlighting other work in progress Looking forward to 2020 with predictions of major themes and open issues</description></item><item><title>Recent Advancements in Container Isolation</title><link>/talks/20181211-recent-advancements-in-container-isolation/</link><pubDate>Tue, 11 Dec 2018 00:00:00 +0000</pubDate><guid>/talks/20181211-recent-advancements-in-container-isolation/</guid><description>Container orchestration enables higher bin-packing and utilization of machines, but native linux containers do not offer the same degree of isolation between workloads as separate VM instances can. Attackers could abuse this lack of isolation to move through a Kubernetes cluster after gaining a foothold in a container. Fortunately, there are many tools in the defenders’ toolbox that can be applied across multiple levels of the stack.
In this survey talk, we will look at several recent or upcoming advancements in container isolation.</description></item><item><title>Security Through the Ages</title><link>/talks/20181210-state-of-security/</link><pubDate>Mon, 10 Dec 2018 00:00:00 +0000</pubDate><guid>/talks/20181210-state-of-security/</guid><description>First, we&amp;rsquo;ll stroke your egos by reviewing the history of Kubernetes security and marvelling in the progress we&amp;rsquo;ve made. Next, we&amp;rsquo;ll examine some of the hottest new features, and how you might be affected. We&amp;rsquo;ll conclude with a call to arms by highlighting a few of the most gnarly issues on the horizon.</description></item><item><title>Layers of Isolation in Kubernetes</title><link>/talks/20181115-layers-of-isolation/</link><pubDate>Thu, 15 Nov 2018 00:00:00 +0000</pubDate><guid>/talks/20181115-layers-of-isolation/</guid><description>How much isolation can you reasonably expect between two applications in the same cluster? Should every application have its own namespace? Every service? Between containers, pods, nodes, namespaces, and even clusters, it can be hard to know how to architect a secure system, and what layers of isolation can be depended on.
In this talk we will start at the bottom and build up. You will learn which resources are isolated between two containers in the same pod, and which are not.</description></item><item><title>Secure Pods</title><link>/talks/20180504-secure-pods/</link><pubDate>Fri, 04 May 2018 00:00:00 +0000</pubDate><guid>/talks/20180504-secure-pods/</guid><description>What is a &amp;ldquo;secure pod&amp;rdquo;? What does it mean for a Kubernetes workload to have strong isolation? With the announcement of Kata Containers and the overflowing multitenancy deep-dive at the last Kubecon, it&amp;rsquo;s clear that these topics are building momentum.
This talk will cover the current state of container isolation and why there is a need for technologies like hypervisor-based containers in order to provide stronger security boundaries. It will also include a discussion of how these technologies fit into Kubernetes and a roadmap for secure pods.</description></item><item><title>About me</title><link>/about/</link><pubDate>Sun, 29 Oct 2017 00:00:00 +0000</pubDate><guid>/about/</guid><description>My name is Tim Allclair (né St. Clair). I am a software engineer at Google working on Kubernetes.
Aside from software engineering and computer security, I enjoy lots of hobbies including piano, woodworking, backpacking, birding, juggling, photography, meditation, and many more&amp;hellip;
@tallclair @tallclair tim-allclair stackoverflow timallclair@gmail.com PGP Key: [4096R/0x5E6F2E2DA760AF51] --</description></item></channel></rss>