Container Security, 2hd Edition / Безопасность контейнеров, 2-е издание
Год издания: 2026
Автор: Rice Liz / Райс Лиз
Издательство: O’Reilly Media, Inc.
ISBN: 979-8-341-62770-3
Язык: Английский
Формат: PDF/EPUB
Качество: Издательский макет или текст (eBook)
Интерактивное оглавление: Да
Количество страниц: 271
Описание: As containerized and cloud native applications become foundational to modern software infrastructure, the need for a deep, conceptual understanding of their security implications has never been more urgent. Container Security, second edition, offers a rigorous yet practical examination of the technologies that underpin container platforms—equipping developers, operations professionals, and security practitioners with the mental models needed to evaluate risk and enhance resilience.
Written by Liz Rice, a recognized authority in cloud native security, this updated edition builds on the foundational principles from the first edition while incorporating today's evolving threat landscape, modern tooling, and advancements in platforms like Kubernetes and Linux. Readers will gain a firm grasp of the architectural components behind containers and the Linux primitives that support them, fostering a systems-level understanding of both threats and mitigation strategies.
Examine the technical underpinnings of containers through a security-focused lens
Evaluate evolving risks and defenses across container runtimes and orchestration platforms
Analyze the implications of modern tooling including eBPF and AI-driven approaches
Apply core principles to assess and secure real-world deployments in dynamic environments
По мере того как контейнерные и облачные приложения становятся основой современной программной инфраструктуры, потребность в глубоком концептуальном понимании их влияния на безопасность становится как никогда актуальной. Книга «Безопасность контейнеров», второе издание, представляет собой тщательное, но в то же время практическое исследование технологий, лежащих в основе контейнерных платформ. Она поможет разработчикам, специалистам по эксплуатации и практикам в области безопасности сформировать ментальные модели, необходимые для оценки рисков и повышения отказоустойчивости.
Это обновлённое издание, написанное Лиз Райс, признанным экспертом в области облачной безопасности, основано на фундаментальных принципах первого издания и учитывает современные угрозы, инструменты и достижения в таких платформах, как Kubernetes и Linux. Читатели получат чёткое представление об архитектурных компонентах контейнеров и поддерживающих их примитивах Linux, что поможет им понять как угрозы, так и стратегии их устранения на системном уровне.
Изучите техническую основу контейнеров с точки зрения безопасности
Оценивайте меняющиеся риски и средства защиты в средах выполнения контейнеров и на платформах оркестрации
Анализируйте возможности современных инструментов, включая eBPF и подходы на основе искусственного интеллекта
Применяйте основные принципы для оценки и защиты реальных развертываний в динамичных средах
Примеры страниц (скриншоты)
Оглавление
Preface. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . xi
1. Container Security Threats. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1
Risks, Threats, and Mitigations 2
Container Threat Model 3
Security Boundaries 7
Multitenancy 8
Shared Machines 9
Virtualization 9
Container Multitenancy 10
Container Instances 11
Security Principles 11
Least Privilege 11
Defense in Depth 12
Reducing the Attack Surface 12
Limiting the Blast Radius 12
Segregation of Duties 12
Applying Security Principles with Containers 12
Summary 13
2. Linux System Calls, Permissions, and Capabilities. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
System Calls 15
File Permissions 17
setuid and setgid 18
Security Implications of setuid 21
Linux Capabilities 21
Privilege Escalation 23
Summary 24
3. Control Groups. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 25
Control Group Controllers 26
Creating and Configuring Cgroups 27
Assigning a Process to a Cgroup 28
Cgroups for Containers 28
Preventing a Fork Bomb 30
Summary 31
4. Container Isolation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
Linux Namespaces 34
Isolating the Hostname 35
Isolating Process IDs 37
Changing the Root Directory 40
Combine Namespacing and Changing the Root 42
Mount Namespace 43
Network Namespace 45
User Namespace 47
Inter-Process Communications Namespace 51
Cgroup Namespace 52
Time Namespace 53
Kubernetes Pods and Container Namespaces 54
Container Processes from the Host Perspective 54
Container Host Machines 56
Summary 57
5. Virtual Machines. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 59
Booting Up a Machine 59
Enter the VMM 61
Type 1 VMMs, or Hypervisors 61
Type 2 VMM 62
Kernel-Based Virtual Machines 63
Trap-and-Emulate 64
Handling Non-Virtualizable Instructions 64
Nested Virtualization 65
KubeVirt 65
Process Isolation and Security 65
Disadvantages of Virtual Machines 67
Container Isolation Compared to VM Isolation 67
Summary 68
6. Container Images. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 69
Root Filesystem and Image Configuration 69
Overriding Config at Runtime 70
OCI Standards 71
Image Configuration 72
Building Images 74
The Dangers of Docker Build 74
Image Layers 76
Multiplatform Images 79
Storing Images 80
Running Your Own Registry 80
Pushing and Pulling 81
Identifying Images 81
Summary 83
7. Supply Chain Security. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 85
Container Image Software Components 86
SLSA 87
Software Bill of Materials 87
Dependency Confusion 88
Package Hallucination 88
Language-Specific SBOMs 88
Minimal Base Images 89
Dockerfile Security 90
Provenance of the Dockerfile 90
Dockerfile Best Practices for Security 91
Attacks on the Build Machine 94
Generating an SBOM 95
Signing Images and Software Artifacts 96
Build Attestations 97
Image Manifests 98
Image Deployment Security 101
Deploying the Right Image 102
Malicious Deployment Definition 102
Verifying the Image Signature and Provenance 102
Admission Control 103
Summary 104
8. Software Vulnerabilities in Images. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 105
Vulnerability Research 105
Vulnerabilities, Patches, and Distributions 107
Application-Level Vulnerabilities 107
Vulnerability Risk Management 108
Vulnerability Scanning 109
Installed Packages 110
Container Image Scanning 110
Immutable Containers 111
Regular Scanning 112
Scanning Tools 112
Sources of Information 113
Out-of-Date Sources 113
Won’t Fix Vulnerabilities 114
VEX Input 114
Subpackage Vulnerabilities 114
Package Name Differences 114
Statically Linked Executables 114
Scanning Multiplatform Images 115
Additional Scanning Features 115
Scanner Errors 116
Scanning in the CI/CD Pipeline 116
Prevent Vulnerable Images from Running 118
Updating Images 119
Zero-Day Vulnerabilities 120
Summary 121
9. Infrastructure as Code and GitOps. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 123
IaC 123
GitOps 124
Implications for Deployment Security 126
GitOps Security Best Practices 128
Summary 129
10. Strengthening Container Isolation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 131
Seccomp 132
AppArmor 134
SELinux 135
gVisor 136
Kata Containers 139
Lightweight/Micro Virtual Machines 139
Unikernels 141
Summary 141
11. Breaking Container Isolation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 143
Containers Run as Root by Default 143
Override the User ID 144
No New Privileges 145
Root Requirement Inside Containers 147
Root for Installing Software 149
Privileges for eBPF and Kernel Modules 150
Rootless Containers 151
The --privileged Flag and Capabilities 153
Mounting Sensitive Directories 156
Mounting the Docker Socket 157
Sharing Namespaces Between a Container and Its Host 157
Sidecar Containers 158
Deploying Sidecars 160
Sidecar Limitations 160
Debug Containers 161
Summary 161
12. Container Network Security. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 163
Container Firewalls and Microsegmentation 163
OSI Networking Model 165
Sending an IP Packet 167
IP Addresses for Containers 168
Network Isolation 169
Layer 3/4 Routing and Rules 170
iptables 170
eBPF 173
Network Policies 174
Layer 3/4 Policy with iptables 175
Layer 3/4 Policies with eBPF 176
Layer 7 Policies 177
Network Policy Solutions 178
Service Mesh 179
Network Policy Best Practices 180
Summary 181
13. Securely Connecting Components. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 183
Secure Connections 183
X.509 Certificates 185
Public/Private Key Pairs 185
Certificate Authorities 187
Certificate Signing Requests 188
TLS Connections 189
WireGuard and IPSec 190
Zero-Trust Networking 192
Secure Connections Between Containers 193
Certificate Revocation 193
Service Meshes for Encrypted Traffic 194
SPIFFE 195
External Traffic 196
Ingress Traffic 196
Egress Traffic 197
Network Observability and Logging 197
Summary 198
14. Passing Secrets to Containers. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 199
Secret Properties 199
Getting Information into a Container 200
Storing the Secret in the Container Image 201
Passing the Secret Over the Network 202
Passing Secrets in Environment Variables 202
Passing Secrets Through Files 203
Kubernetes Secrets 204
Secrets Store CSI Driver 205
External Secrets Operator 205
Rotating Secrets in Kubernetes 205
Secrets Are Accessible by Root 207
Summary 208
15. Container Runtime Protection. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 209
Container Image Runtime Policies 210
Network Traffic 210
Executables 211
File Access 212
User and Group IDs 212
AI for Generating Runtime Policies 213
Technology Options for Runtime Security 213
LD_PRELOAD 213
Ptrace 214
Seccomp, AppArmor, and SELinux 215
Kernel-Based Runtime Security 215
eBPF for Runtime Security 216
Container Runtime Security Tools 219
Falco 219
Cilium Tetragon 220
Tracee 223
Inspektor Gadget 223
Prevention or Alerting 223
Quarantining a Container 225
Vulnerability Mitigation 225
Summary 227
16. Containers and the OWASP Top 10. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 229
Broken Access Control 229
Cryptographic Failures 230
Injection 230
Insecure Design 230
Security Misconfiguration 231
Vulnerable and Outdated Components 232
Identification and Authentication Failure 232
Software and Data Integrity Failures 232
Security Logging and Monitoring Failures 233
Server-Side Request Forgery 233
Summary 234
Conclusions. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 235
Appendix. Security Checklist. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 237
Index. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 241