Cloud Native New Delhi

Secure-i-ous Solutions: Secret to Cloud Native Security

Attendees:
in-person
Event date
Oct 19, 24
09:00 AM - 03:00 PM IST
Location
Microsoft, DLF Downtown Gurugram
About this event

Join us for our upcoming meetup, hosted in collaboration with Microsoft, KubeArmor and OpenSSF, as we explore "Secure-i-ous Solutions: Secrets to Cloud Native Security." In the ever-evolving landscape of cloud technology, ensuring the security of cloud-native systems is more critical than ever. This event aims to raise awareness about cloud security best practices, the importance of protecting cloud environments, and practical risk mitigation strategies.

What to Expect:

  • Expert Insights: Hear from four knowledgeable speakers who will share their expertise on cloud security fundamentals and discuss real-world case studies. Learn how to safeguard your cloud-native applications, implement robust security measures, and respond effectively to potential threats.

  • Interactive Quiz: Test your knowledge of cloud security concepts in a fun and engaging quiz! Participants will have the opportunity to win exciting prizes while deepening their understanding of essential security practices.

  • Networking Session: Connect with fellow attendees during our dedicated networking time. Share ideas, discuss challenges, and build valuable connections with peers who share your passion for cloud security.

  • Share Your Insights!

When you RSVP, you’ll have the opportunity to fill out a form to share your own cloud security experiences. Whether it's a challenge you've faced or a success story, your insights can contribute to a richer dialogue and help others navigate their cloud security journeys.

👉 Important Note: Simply RSVPing does not guarantee your spot. To secure your place, please watch for the confirmation email sent the day before the meetup. This email will serve as your golden ticket to the event, ensuring a smooth experience.

Get ready for a day of learning and exploration in cloud-native security. We look forward to seeing you there!

Agenda
  1. 9:00 AM IST

    Registration

    in-person

    Start of the event, attendee registration and morning munch time.

  2. 9:40 AM IST

    CNCF Updates by Satyam Soni

    in-person

    New updates about the CNCF

  3. 10:00 AM IST

    Modern Security Paradigms by Ram Iyengar

    in-person

    In this session, we will explore the evolving landscape of software security, particularly in the context of containers and open-source software. As software development practices continue to change, the parameters surrounding software—quality, reliability, and security—must evolve at an equally rapid pace. But are they keeping up?

    Join us as we delve into how containers and open-source software have transformed the tooling landscape, especially in terms of security. We will examine key techniques and tools designed to enhance security when working with containers and open-source environments.

    Session Highlights:

    1. The Evolution of Software Security: Understand how security practices are adapting to the rapid changes in software design, building, and consumption.
    2. Containers and Open-Source Impact: Explore how these domains have shifted security tooling and what it means for modern software.
    3. Practical Techniques and Tools: Discover actionable methods to improve security within containerized and open-source environments.
  4. 10:25 AM IST

    AMA

    in-person

    Interactive session with an expert speaker. A platform to engage, learn, and share insights in a community meetup.

  5. 10:35 AM IST

    (Featured Session) Secure Multi-Tenancy with vCluster and Falco: Enhancing Kubernetes Security and Isolation by Saiyam Pathak

    in-person

    In this session, we will explore the use of vCluster to achieve robust tenant isolation by creating separate virtual clusters, ensuring logical separation in shared Kubernetes environments. Additionally, we will delve into Falco, an open-source runtime security tool designed to detect real-time threats and suspicious activities in Kubernetes, such as privilege escalations and unauthorized access.

    This session will highlight best practices for integrating vCluster and Falco to enhance both isolation and threat detection in multi-tenant environments. Attendees will gain actionable insights into building a secure, scalable Kubernetes infrastructure using these tools.

    Session Takeaways:

    1. Tenant Isolation with vCluster: Learn how vCluster enables strong tenant isolation through the creation of distinct virtual clusters.
    2. Threat Detection with Falco: Understand how Falco monitors and detects real-time threats within Kubernetes environments.
    3. Best Practices: Discover how to effectively combine vCluster and Falco to achieve secure multi-tenancy in Kubernetes.
  6. 11:00 AM IST

    AMA

    in-person

    Interactive session with an expert speaker. A platform to engage, learn, and share insights in a community meetup.

  7. 11:10 AM IST

    Govern Application Deployments on Kubernetes with Policy as Code Using Kyverno by Vinod Kumar

    in-person

    In this session, we will provide an in-depth overview of Kyverno, a Kubernetes-native policy engine and an incubating project of CNCF, designed to simplify the management and governance of application deployments through Policy as Code. We’ll begin by exploring how authorization works in Kubernetes to set the foundation for understanding Kyverno’s capabilities. The session will wrap up with a hands-on demonstration, where attendees will learn to write and apply policies in YAML to effectively govern their application deployments, followed by an interactive Q&A.

    Key Takeaways:

    1. Understanding Policy as Code: Learn how Kyverno makes governance straightforward by using YAML-based policies.
    2. Kubernetes Governance: Discover how Kyverno enforces security and compliance natively within Kubernetes environments.
    3. Hands-on Demonstration: See Kyverno in action as we demonstrate policy enforcement during application deployments.
    4. Real-World Applications: Understand how to leverage Kyverno for automating security, validation, and resource management in your Kubernetes clusters.
  8. 11:35 AM IST

    AMA

    in-person

    Interactive session with an expert speaker. A platform to engage, learn, and share insights in a community meetup.

  9. 11:45 AM IST

    Chai & Coffee Break

    in-person

    Refresh, network, and recharge with a warm cup!

  10. 12:00 PM IST

    Patch It Up: Real-Time Vulnerability Management with Kyverno and KubeArmor by Barun Acharya

    in-person

    In this session, we will explore how organizations can go beyond traditional security best practices, such as using Admission Controllers like Kyverno and Static Analysis tools, to protect against emerging vulnerabilities. While effective, these measures may not always safeguard applications against newly discovered threats. Since application upgrades can take time, it can be more practical to sandbox these vulnerabilities rather than wait for upstream fixes.

    We will dive into the concept of virtual patching—an approach to contain and prevent the exploitation of vulnerabilities at runtime without affecting application behaviour or deployment processes, thereby preventing downtime.

    Session Highlights:

    1. Addressing Future Vulnerabilities: Learn why static analysis and admission controls may fall short in protecting against new threats.
    2. Virtual Patching: Understand how virtual patching can help contain vulnerabilities without impacting applications.
    3. Live Demonstrations: Explore real-world examples using well-known vulnerabilities, such as Log4j, PwnKit, xz, and Leaky Vessels.
    4. Kyverno and KubeArmor Integration: See how to use Kyverno to identify vulnerable workloads, leverage image vulnerability scanners, and create KubeArmor policies for applying virtual patches, ensuring robust security without operational disruption.
  11. 12:25 PM IST

    AMA

    in-person

    Interactive session with an expert speaker. A platform to engage, learn, and share insights in a community meetup.

  12. 12:35 PM IST

    End to End Enterprise Security for Kubernetes by Hemant Rathore

    in-person

    In this session, we will explore comprehensive strategies and best practices for securing Kubernetes environments from start to finish. We’ll cover the critical components of enterprise security, from initial deployment configurations to ongoing threat detection and response. Attendees will gain insights into safeguarding Kubernetes clusters against potential vulnerabilities, ensuring robust protection and compliance across the entire infrastructure.

    Whether you’re an experienced Kubernetes professional or just beginning your journey, this talk will provide the essential knowledge needed to maintain a secure and resilient enterprise ecosystem.

    Session Highlights:

    1. End-to-End Security: Learn how to secure Kubernetes environments, starting from deployment configurations to continuous monitoring.
    2. Enterprise Security Essentials: Delve into critical components necessary for robust protection and compliance within enterprise Kubernetes clusters.
    3. Proactive Threat Detection: Explore best practices for ongoing threat detection and response to maintain cluster security.
    4. Actionable Insights: Gain practical guidance to build and maintain a secure, resilient Kubernetes ecosystem, regardless of your current expertise level.
  13. 1:00 PM IST

    AMA

    in-person

    Interactive session with an expert speaker. A platform to engage, learn, and share insights in a community meetup.

  14. 1:10 PM IST

    Breakout session (Follows Chatham House Rules)

    in-person

    In this engaging breakout session, attendees will be split into groups and assigned to different rooms. Each group will tackle a series of exciting tasks designed to test creativity, collaboration, and problem-solving skills. Compete with your peers to complete the challenges with flair. The group that demonstrates the most innovative and effective solutions will be crowned the winners! Get ready to think outside the box and showcase your teamwork prowess. May the best team win! 🌟

  15. 1:45 PM IST

    Quiz

    in-person

    Dive into our exciting quiz, where your session savvy could lead to victory! Test your knowledge, compete for glory, and have a blast! 🧠🏆

  16. 2:00 PM IST

    Lunch and Networking!

    in-person

    Dedicated time for attendees to munch, network, establish connections, and bond over shared interests.

  17. 3:00 PM IST

    Lights off

    in-person

    See you folks at the Next Event.

Speakers
Organizers