Kubernetes Security Overview

In this Cloud Native Short Take, Chris Hanson covers the Kubernetes Security Overview module. The module covers essential topics such as authN and authZ mechanisms, pod security context, and namespaces, including limiting namespaces through the use of quotas. In the video Chris demonstrates how to use quotas to prevent users in one namespace from starving other namespaces of resources.

Video Transcript

Welcome to another Cloud Native Short Take, my name is Chris Hanson and today we’re going to be covering the Kubernetes Security Overview module. In this module we cover topics such as authN and authZ mechanisms, pod security topics such as security context, as well as namespaces, and limiting namespaces through the use of quotas. And that leads us to the demo for today’s short take.

Taking a look at our nodes we’ve got a small cluster of two core four gig memory boxes, one of which is our single control plane. If we look at how saturated our worker nodes are, right now they’re relatively idle at ten percent. Now the problem statement here is that any user that creates pods is of course going to consume the cpu and memory of our workers. There is a potential that one set of users within a namespace can starve other users and other namespaces simply by using up the cpu and memory in the cluster. 

So let’s take a look at our Deployment and you can see that it’s got a request and limit for cpu and memory. So if we deploy that and then rerun the describe command on our nodes you can see that now our nodes are about 90 percent saturated. Now if I try to deploy something else–this is an identical Deployment of the same number of replicas with the same request–it’s just going to run in the beta namespace whereas the first one ran in the alpha namespace. You can see that in the alpha namespace my pods are fine; they’re running, they’re consuming cpu and memory per their requests and limits, but in the beta namespace I can’t deploy anything because essentially I’m out of resources. You can see when I describe this pod that the event stream is telling us just that one node is tainted–that’s the control plane node–and the other two have insufficient resources for my pods. So now I’ve effectively starved namespace beta because namespace alpha is consuming all the resources.

This is where quotas come in. So first let’s clear our cluster. Now let’s take a look at our quota. What this resource quota will do isl effectively limit the amount of cpu and memory that can be consumed by the alpha namespace. Now if I redeploy my pods in the alpha namespace I can see that although I want four pods I can only deploy two because the quota is going to limit what I can deploy. Looking at the event stream for the replicaSet shows me that there are errors being thrown in the API because the replicaSet is going to keep trying to create the pods but of course the API is going to say “no you can’t do that because it violates the quota”. What this allows is that now I can deploy things in the beta namespace.

Now really neither namespace has an ideal scenario where they can deploy everything because this is a small cluster and just a demo but the idea is now users in the beta namespace can work right? Users in the alpha namespace cannot starve the beta namespace of resources or any other namespace frankly on the cluster. 

From a security standpoint, let’s say a user credential is compromised and that user credential tries to consume the entire Kubernetes cluster. They’re going to be limited right? They can’t do that–so that we don’t essentially DoS all the other applications by starving them of resources! 

That’s just one of the things that you’ll learn in the Kubernetes Security Overview module from RX-M. If you click on the Training menu here on our site, then choose Custom Course Builder, on that page, scroll down and find the “Modules” column and open up the Kubernetes section. Find the Security Overview module and drag it to your custom course. You can add it among other modules to a custom course that fits the needs of your team. 

Thanks for joining us today! That was our Cloud Native Short Take on the Kubernetes Security Overview module.

Secret Link