or
or
By clicking below, you agree to our terms of service.
New to HackMD? Sign up
Syntax | Example | Reference | |
---|---|---|---|
# Header | Header | 基本排版 | |
- Unordered List |
|
||
1. Ordered List |
|
||
- [ ] Todo List |
|
||
> Blockquote | Blockquote |
||
**Bold font** | Bold font | ||
*Italics font* | Italics font | ||
~~Strikethrough~~ | |||
19^th^ | 19th | ||
H~2~O | H2O | ||
++Inserted text++ | Inserted text | ||
==Marked text== | Marked text | ||
[link text](https:// "title") | Link | ||
 | Image | ||
`Code` | Code |
在筆記中貼入程式碼 | |
```javascript var i = 0; ``` |
|
||
:smile: | ![]() |
Emoji list | |
{%youtube youtube_id %} | Externals | ||
$L^aT_eX$ | LaTeX | ||
:::info This is a alert area. ::: |
This is a alert area. |
On a scale of 0-10, how likely is it that you would recommend HackMD to your friends, family or business associates?
Please give us some advice and help us improve HackMD.
Do you want to remove this version name and description?
Syncing
xxxxxxxxxx
Kubernetes Security
Policy Enforcement
lalyos
Topics
Cloud Native ???
mit adtak nekunk a romaiak ( Docker )?
solving: "it was running on my machine" ™
packaging format (tar.gz of layers)
containerd + runc
microservices 12factor.net
k8s: run containers on a lot of servers
Cloud Native Security - 4C
Cloud Layer (1) - Infrastructure
Cluster Layer (2)
Container Layer (3)
Code Layer (4)
Cluster Layer - Secrets
Container Layer - Runtimes
Docker = dockerd + containerd + runc
k8s = CRI (containerd/crio) + runc/kata/firecracker/gvisor/wasm …
Policy Enforcement - best practices
There are industry wide best practices:
Policies - how to enforce them
Policies - CNCF landscape
Policy Enforcement - OPA
Policy Enforcement - Kyverno
Admission Controller
Policies - Kyverno
Keep in touch