Policy enforcement with GitOps – using OPA Gatekeeper and ArgoCD

Policy enforcement with GitOps – using OPA Gatekeeper and ArgoCD

HomeContainers from the CouchPolicy enforcement with GitOps – using OPA Gatekeeper and ArgoCD
Policy enforcement with GitOps – using OPA Gatekeeper and ArgoCD
ChannelPublish DateThumbnail & View CountDownload Video
Channel AvatarPublish Date not found Thumbnail
0 Views
Combining policy enforcement with GitOps can help protect your environment from known threat vectors and deal with changes such as updates to the container image registry. In this video, Lukonde Mwila covers access control in Kubernetes, the importance of policy enforcement, and shows how you can combine OPA Gatekeeper and ArgoCD to automate guardrails for your cluster. The main example in this video deals with blocking images from the legacy Kubernetes container image registry (k8s.gcr.io).

00:00 – Important updates in Kubernetes 1.25
00:12 – Changes to the Kubernetes container image registry
00:25 – Policy enforcement and GitOps
02:17 – Access control in Kubernetes
04:38 – Using RBAC to prevent reads in your Kubernetes cluster
04:53 – OPA Gatekeeper explained
08:14 – Writing and testing OPA policies
12:51 – OPA Restriction Templates and Restrictions
15:19 – Demo: OPA Gatekeeper breach detection through auditing
18:37 – Demo: Blocking the creation of invalid resources with OPA Gatekeeper

Additional resources:
Argo CD – https://argo-cd.readthedocs.io/en/stable/
OPA Gatekeeper – https://github.com/open-policy-agent/gatekeeper
The Rego Playground – https://play.openpolicyagent.org/

Short videos:
Difference between k8s.gcr.ip and registry.k8s.io #kubernetes – https://youtube.com/shorts/5RvrkLPImGQ
How to fix registry.k8s.io issues in EKS – https://youtube.com/shorts/iPxTkesO3Mo

EKS best practices examples – https://github.com/aws/aws-eks-best-practices/tree/master/policies/k8s-registry-deprecation

Blog posts:
Changes to the Kubernetes Container Image Registry – https://aws.amazon.com/blogs/containers/changes-to-the-kubernetes-container-image-registry
registry.k8s.io: faster, cheaper and generally available (GA) – https://kubernetes.io/blog/2022/11/28/registry-k8s-io-faster-cheaper-ga/
The k8s.gcr.io image registry will be frozen starting April 3, 2023 – https://kubernetes.io/blog/2023/02/06/k8s-gcr-io-freeze-announcement/
k8s.gcr.io Redirect to registry.k8s.io – What you need to know – https://kubernetes.io/blog/2023/03/10/image-registry-redirect/#why-is-a-redirect-being-put-in-place

#AWS #EKS #Kubernetes

Please take the opportunity to connect with your friends and family and share this video with them if you find it useful.