Kubernetes Security Specialist (CKS): Exam Cram Notes by Specialist IP
Author:Specialist, IP
Language: eng
Format: epub
Published: 2022-05-15T00:00:00+00:00
As shown in Figure 4-02, if the setting called a hostIPC= true is set to true, containers will use the host's interprocess communication namespace. Interprocess communication is just a feature of Linux that allows processes to communicate. Normally, our containers use a separate IPC namespace, which means there is no way for a container process to communicate with other processes on the host or with other containers. This limits the potential for an attacker to utilize that to potentially interact with and compromise other system components. So, if we set host IPC to true, the containers in this Pod will be utilizing the host IPC namespace. However, we must avoid this setting because the isolation provided by having a separate namespace is beneficial to security. Another setting, called hostnetwork, controls the network namespace, where we have hostPID. If we set it to true, containers will use the host process ID namespace. All three of these settings instruct our containers to use the host namespace in each one of those different areas rather than using their own separate isolated namespace. As all of these settings are set to false, by default, if you do not specify any of those three settings, you can rest easy knowing that your containers are properly isolated using their namespaces rather than the host namespace. Thus, the most important thing to remember is to use hostIPC, hostNetwork, and hostPID only when necessary. Do not use settings unnecessarily because it is good from a security standpoint to have that isolation and not use the host namespace.
Download
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
The Art of Coaching Workbook by Elena Aguilar(51000)
Trainspotting by Irvine Welsh(21521)
Twilight of the Idols With the Antichrist and Ecce Homo by Friedrich Nietzsche(18510)
Fangirl by Rainbow Rowell(9104)
Periodization Training for Sports by Tudor Bompa(8173)
Change Your Questions, Change Your Life by Marilee Adams(7638)
This Is How You Lose Her by Junot Diaz(6800)
Asking the Right Questions: A Guide to Critical Thinking by M. Neil Browne & Stuart M. Keeley(5653)
Grit by Angela Duckworth(5525)
Red Sparrow by Jason Matthews(5392)
Paper Towns by Green John(5092)
Room 212 by Kate Stewart(5041)
Ken Follett - World without end by Ken Follett(4647)
Housekeeping by Marilynne Robinson(4349)
The Sports Rules Book by Human Kinetics(4299)
Double Down (Diary of a Wimpy Kid Book 11) by Jeff Kinney(4209)
Papillon (English) by Henri Charrière(4199)
The Motorcycle Diaries by Ernesto Che Guevara(4018)
Exercise Technique Manual for Resistance Training by National Strength & Conditioning Association(3960)