TGViewer
DevOps MemOps DevOps MemOps @devops_memops · 6.34K subscribers
Post #7196 1.56K
Доклад “Sandboxes, Seccomp, and Syscalls: Chasing Isolation in Kubernetes” от Mark Manning посвящён одной из самых сложных тем в Kubernetes — изоляции контейнеров и реальной безопасности sandbox-окружений.

Автор подробно разбирает, почему контейнеры сами по себе не являются полноценной границей безопасности, какие ограничения есть у seccomp и где проходит граница между виртуализацией и изоляцией. Особенно интересно, что в докладе рассматриваются не только способы защиты workload’ов, но и реальные сценарии обхода sandbox-механизмов.

Доклад будет полезен всем, кто работает с multi-tenant Kubernetes-кластерами и хочет лучше понимать риски container isolation.

📌 Подробнее: https://www.youtube.com/watch?v=AKimmv-OYgE

MemOps 🤨
YouTube BSidesSF 2026 - Sandboxes, Seccomp, and Syscalls: Chasing Isolation in Kubernetes (Mark Manning) Sandboxes, Seccomp, and Syscalls: Chasing Isolation in Kubernetes Mark Manning Containers aren’t a security boundary — but we love dangerous things. This talk dives into real-world k8s sandboxing: sharp edges of seccomp, lines between virtualization and…
  • ❤ 1
  • 👍 1
More from @devops_memops
  1. Oct 6, 2026Post #8359
  2. Oct 5, 2026MemOps 😃
  3. Oct 5, 2026Post #8352
  4. Oct 5, 2026nvitop — интерактивный просмотрщик процессов NVIDIA-GPU и не только, универсальное решение…
  5. Oct 5, 2026MemOps 😃
  6. Oct 5, 2026Tempo 3.1 release: new features for Kafka, TraceQL metrics updates, trace redaction, and m…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →