gVisor and Falco - Strengthening Kubernetes and Container Security with Visibility
CNCF [Cloud Native Computing Foundation] via YouTube
Overview
Syllabus
Intro
It takes a team!
Container sandboxing security challenge
About Falco
How Falco works
Running Falco
How gVisor works
Prevention != Detection
gVisor isolation confused Falco
gVisor Kernel to the rescue!
One Falco instance per node
Falco architecture evolution
Calling on the community
Falco+gVisor user benefits
Taught by
CNCF [Cloud Native Computing Foundation]