BEGIN:VCALENDAR
PRODID:-//Google Inc//Google Calendar 70.9054//EN
VERSION:2.0
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:44CON 2026
X-WR-TIMEZONE:Europe/London
BEGIN:VEVENT
DTSTART:20260917T135000Z
DTEND:20260917T144000Z
DTSTAMP:20260624T151157Z
UID:7io71slqhen77fjolrlrtnhd38@google.com
CREATED:20260624T102212Z
DESCRIPTION:One of the attractions of Kubernetes is being able to save m
 oney on cloud bills\, and what better way to save money that running everyt
 hing in one massive cluster with all our different teams (or customers) dep
 loying their applications in one place! Unfortunately once we’ve got our cl
 uster set-up we might end up singing the multi-tenant blues as it can be a 
 bit tricky to isolate our workloads properly.\nWe’re going to talk abo
 ut the different layers that make up a Kubernetes cluster and how the stack
  of different projects and re-use of older Linux primitives makes good mult
 i-tenant security hard to achieve. We’ll also look at some of the risks of 
 breakout from containers down to shared cluster nodes\, how the Kubernetes 
 authorization system has edge cases that can allow for privilege escalation
  and why the networking model implemented by Kubernetes does not lend itsel
 f to scenarios where hostile tenants are present\, especially as Kubernetes
  is SSRF as a service!\nWe’ll also look at a high-level at how these p
 roblems can be solved and the trade-offs of different approaches to improvi
 ng multi-tenant Kubernetes cluster security\, so that attendees can make in
 formed decisions on where they want to place the security boundaries in the
 ir Kubernetes environments.
LAST-MODIFIED:20260624T150846Z
LOCATION:Track 1
SEQUENCE:0
STATUS:CONFIRMED
SUMMARY:Kubernetes Multi-Tenant Blues – Rory McCune
TRANSP:OPAQUE
END:VEVENT
END:VCALENDAR