youtube image
From YouTube: Getting Your Hands "Dirty" in Container Sandbox - Ariel Shuper, Aqua Security


Join us for Kubernetes Forums Seoul, Sydney, Bengaluru and Delhi - learn more at

Don't miss KubeCon + CloudNativeCon 2020 events in Amsterdam March 30 - April 2, Shanghai July 28-30 and Boston November 17-20! Learn more at The conference features presentations from developers and end users of Kubernetes, Prometheus, Envoy, and all of the other CNCF-hosted projects

Getting Your Hands "Dirty" in Container Sandbox - Ariel Shuper, Aqua Security

The session addresses the proliferation of "sandboxing" techniques to isolate containers and improve their security posture. It'll provide a short background on the rise of "sandboxing" technology in the global security space and will drill down into different containers "sandboxing" technologies/projects. It'll examine and compare different sandboxing initiatives: Google's gVisor, Openstack's Katacontainers, Hardware based initiative (containers "enclaves") as opposed to legacy Linux isolation tools applied for Containers (SELinux and Seccomp). It'll analyze the benefit and the challenges of each implementation and will demonstrate the attacks types sandboxing/isolation technologies can mitigate vis-a-vis the attacks which sandboxing/isolation technologies can't mitigate and require additional security layers.

To learn more: