CNS-413

Practical Cloud Native Security

Harden Kubernetes clusters, containerized applications, and delivery workflows while preparing for the CKS certification and aligning with NESAS requirements.

Course Description

This 3-day training delivers hands-on knowledge in cloud-native security. It introduces concepts, procedures, and best practices for hardening Kubernetes-based systems and container workloads against modern threats. Participants explore every major area of cloud-native security—from cluster setup and operating system hardening to supply chain integrity and runtime protections—while preparing for the Certified Kubernetes Security Specialist (CKS) exam and aligning with GSMA NESAS security requirements.

Training Objectives

At the end of the training participants:

  • Understand the core cloud-native security concepts: Pod Security Standards and OpenShift Security Context Constraints, RBAC, network policies, namespaces and quotas, secrets and auditing.
  • Harden containers as a developer with minimal and UBI images, non-root execution, capabilities, seccomp and the Security Profiles Operator.
  • Integrate policy aware admission and supply chain security steps such as SBOM generation, scanning, signing and verification into CI/CD pipelines.
  • Harden clusters as an infrastructure maintainer with FIPS, the Machine Config Operator, node immutability, the Compliance Operator and the File Integrity Operator.
  • Implement multi-tenancy, forward logs and audit data to a SIEM and detect runtime threats with Falco and eBPF based sensors.
  • Operate air-gapped environments with oc mirror, ImageContentSourcePolicy, image provenance enforcement and Harbor.
  • Automate security testing with Conftest and Kyverno in CI and perform API fuzz testing as well as combined performance and security validation.
  • Secure application delivery with onboarding playbooks and evidence packs for audits.
  • Be prepared for the official Certified Kubernetes Security Specialist (CKS) exam of the Cloud Native Computing Foundation (CNCF).

Main Topics

  • Core cloud-native security concepts: SCC vs PSS, RBAC, network policies, namespaces, secrets, auditing
  • Container and image hardening strategies for developers
  • Policy-aware admission and CI/CD integration for security gates
  • Kubernetes cluster hardening, compliance, and monitoring
  • Multi-tenancy, logging pipelines, Falco/eBPF runtime sensors
  • Operating in air-gapped environments with secure registries
  • Security test automation, fuzzing, and performance governance
  • Securing delivery pipelines with onboarding playbooks and audit evidence

Target Audience

System administrators, developers, and DevOps engineers who need to understand and implement cloud-native security in practice.

Prerequisites

Linux container knowledge and Kubernetes administration skills (e.g., Component Soft Docker and Kubernetes courses).

Duration

3 days

Ár és időpont

Nettó ár420 000 Ft
Dátum (online)november 2-9, AMER: 10-14 EST, EMEA: 14-18 CET