← Back
Mischa Vandenburg April 10, 2024 1h 36m

šŸ“š K8s Studies - CKS Certification - Killercoda & Containers!

Read full transcript 57 segments
  1. okay waiting for the stream okay waiting for the stream to go fully online waiting until I see the preview online waiting until I see the preview in my little window here so for those of you who have been here so for those of you who have been following along with the the study following along with the the study following along with the the study streams I have made quite a lot of streams I have made quite a lot of streams I have made quite a lot of progress in the course uh of stream I've progress in the course uh of stream I've progress in the course uh of stream I've had some time in between thing in had some time in between thing in had some time in between thing in between um days between um days between um days but uh I didn't have the time or energy but uh I didn't have the time or energy but uh I didn't have the time or energy to actually do live streaming of it so I to actually do live streaming of it so I to actually do live streaming of it so I have progressed quite far but on the have progressed quite far but on the have progressed quite far but on the other hand all of the stuff wasn't that other hand all of the stuff wasn't that other hand all of the stuff wasn't that interesting to stream I think but it was interesting to stream I think but it was interesting to stream I think but it was very interesting to learn about uh very interesting to learn about uh very interesting to learn about uh everything and I'm making good progress everything and I'm making good progress everything and I'm making good progress in the killer Koda in the killer shell in the killer Koda in the killer shell in the killer Koda in the killer shell scenarios that I'm following with all of scenarios that I'm following with all of scenarios that I'm following with all of the with the course as he the with the course as he the with the course as he recommends let's see what is the recommends let's see what is the recommends let's see what is the status those are checked that's checked looks like I have about half of checked looks like I have about half of the killer Koda scenarios the killer Koda scenarios the killer Koda scenarios done so I'm now about done so I'm now about done so I'm now about to to to do the ones about let me see the do the ones about let me see the do the ones about let me see the container footprint here container container footprint here container container footprint here container footprint user and container footprint user and container footprint user and container hardening uh so that's going to be an hardening uh so that's going to be an hardening uh so that's going to be an interesting one and I also have a interesting one and I also have a interesting one and I also have a container image for an application I've container image for an application I've container image for an application I've been working on for my home lab that I

  2. been working on for my home lab that I been working on for my home lab that I want to harden a little bit or at least want to harden a little bit or at least want to harden a little bit or at least reduce the footprint so I'm going to do reduce the footprint so I'm going to do reduce the footprint so I'm going to do that and I want to just repeat uh a that and I want to just repeat uh a that and I want to just repeat uh a couple of them one of them being um API couple of them one of them being um API couple of them one of them being um API server misconfigured that's that was a server misconfigured that's that was a server misconfigured that's that was a really fun one and actually I think I'm really fun one and actually I think I'm really fun one and actually I think I'm just going to start with that one so I've really gotten into the habit of so I've really gotten into the habit of starting as soon as I get into the starting as soon as I get into the starting as soon as I get into the scenario like this I start t-o right scenario like this I start t-o right scenario like this I start t-o right away and set- OVI that this makes away and set- OVI that this makes away and set- OVI that this makes everything so much easier and it has everything so much easier and it has everything so much easier and it has been so annoying to not have set- o VII been so annoying to not have set- o VII been so annoying to not have set- o VII so I'm just typing it with every so I'm just typing it with every so I'm just typing it with every scenario all the time now just making my scenario all the time now just making my scenario all the time now just making my camera a little bit smaller here so that camera a little bit smaller here so that camera a little bit smaller here so that you actually are able to see all right all right let's start this see all right all right let's start this scenario make sure to have solved the scenario make sure to have solved the scenario make sure to have solved the previous scenario API server crash the previous scenario API server crash the previous scenario API server crash the API server is not coming up the Manifest API server is not coming up the Manifest API server is not coming up the Manifest is misconfigured in three places fix it is misconfigured in three places fix it is misconfigured in three places fix it okay so let's start by seeing if we can okay so let's start by seeing if we can okay so let's start by seeing if we can see see anything about the API server in see see anything about the API server in see see anything about the API server in the crl because I cannot do kg get pods the crl because I cannot do kg get pods the crl because I cannot do kg get pods because the API server is down because the API server is down because the API server is down obviously hopefully you can can see the

  3. obviously hopefully you can can see the obviously hopefully you can can see the the text now it's big enough for you so the text now it's big enough for you so the text now it's big enough for you so I'm going to start with looking at the I'm going to start with looking at the I'm going to start with looking at the CRI CTL the container runtime interface CRI CTL the container runtime interface CRI CTL the container runtime interface PS and we don't see anything about the PS and we don't see anything about the PS and we don't see anything about the API server here here so I'm going to API server here here so I'm going to API server here here so I'm going to check out the logs oh that's annoying why isn't it logs oh that's annoying why isn't it registering my contrl L to clear the registering my contrl L to clear the registering my contrl L to clear the screen normally does that that's screen normally does that that's screen normally does that that's annoying well anyway um I'm going to annoying well anyway um I'm going to annoying well anyway um I'm going to check out the logs for past pods so if I check out the logs for past pods so if I check out the logs for past pods so if I go to CD VAR go to CD VAR go to CD VAR log and then pod pods and LS here then log and then pod pods and LS here then log and then pod pods and LS here then here there should be a no there is no here there should be a no there is no here there should be a no there is no API server actually okay so the there API server actually okay so the there API server actually okay so the there are no pod logs from any API so just LS are no pod logs from any API so just LS are no pod logs from any API so just LS and then grab API here we see we get no and then grab API here we see we get no and then grab API here we see we get no nothing back so then I'm starting to nothing back so then I'm starting to nothing back so then I'm starting to think that it must be in the CIS log so think that it must be in the CIS log so think that it must be in the CIS log so I'll do Journal I'll do Journal I'll do Journal CTL CTL CTL oh Journal oh Journal oh Journal CTL and then I go all the way way to the CTL and then I go all the way way to the CTL and then I go all the way way to the bottom and if I then press oh I should bottom and if I then press oh I should bottom and if I then press oh I should turn on my key Caster actually just do not disturb for an

  4. actually just do not disturb for an hour and I'll have to turn on key Caster hour and I'll have to turn on key Caster hour and I'll have to turn on key Caster so you can see my key so you can see my key so you can see my key presses okay so now you can see those presses okay so now you can see those presses okay so now you can see those and while I'm edit I'm also just going and while I'm edit I'm also just going and while I'm edit I'm also just going to start my Pomo timer Pomo start so now I'm uh starting a 50 minute promo so now I'm uh starting a 50 minute promo I might do one and a half maybe two I might do one and a half maybe two I might do one and a half maybe two we'll see how far how far I we'll see how far how far I we'll see how far how far I go so I'm in CIS log going all the way go so I'm in CIS log going all the way go so I'm in CIS log going all the way down and I'm pressing question mark to down and I'm pressing question mark to down and I'm pressing question mark to search search search upwards and API let's see I'm searching for API let's see I'm searching for API here I see something about API API here I see something about API API here I see something about API server you see server you see server you see that names space Cube system Cube API that names space Cube system Cube API that names space Cube system Cube API server control server control server control plane connection something connection reviews something connection reviews yeah it's obvious that there is connection it's obvious that there is connection refused because it's not refused because it's not refused because it's not up up up here here we see something about here here we see something about here here we see something about manifest error ATC manifest QBE API manifest error ATC manifest QBE API manifest error ATC manifest QBE API server couldn't

  5. server couldn't server couldn't parse as po yaml line four could not parse as po yaml line four could not parse as po yaml line four could not find find find expected uh colon so here we have a hint expected uh colon so here we have a hint expected uh colon so here we have a hint here so I'm going to open my here so I'm going to open my here so I'm going to open my pane a new pane I'm going to go to Etc pane a new pane I'm going to go to Etc pane a new pane I'm going to go to Etc manif kubernetes manif kubernetes manif kubernetes manifests and I have the cube ABI manifests and I have the cube ABI manifests and I have the cube ABI server. yaml and I'm going server. yaml and I'm going server. yaml and I'm going to open that one in vim and here we go to open that one in vim and here we go to open that one in vim and here we go there is metadata there is a what what's there is metadata there is a what what's there is metadata there is a what what's that is it's not a colon right or is that is it's not a colon right or is that is it's not a colon right or is that a colon well anyway I have to turn that a colon well anyway I have to turn that a colon well anyway I have to turn it into this one and now we actually it into this one and now we actually it into this one and now we actually have a valid pod have a valid pod have a valid pod manifest so now we should at least see a manifest so now we should at least see a manifest so now we should at least see a pod coming up in cctl actually in this window I'm going cctl actually in this window I'm going to just do watch to just do watch to just do watch N1 CRI N1 CRI N1 CRI CPS so now I can just see exactly what's CPS so now I can just see exactly what's CPS so now I can just see exactly what's going on and I should see the API server going on and I should see the API server going on and I should see the API server come up come up come up soon in in the sis log that I need to check in in the sis log that I need to check so Journal CTL so Journal CTL so Journal CTL again go all the way

  6. down let's see fil to down let's see fil to [Music] control we see some errors here but control we see some errors here but maybe it has it has run maybe I should maybe it has it has run maybe I should maybe it has it has run maybe I should just check out CD VAR log pod snow do we ah now we see something about snow do we ah now we see something about the API server so I do just to make sure the API server so I do just to make sure the API server so I do just to make sure LS grab API and now we see that we have LS grab API and now we see that we have LS grab API and now we see that we have a directory here called Cube API server a directory here called Cube API server a directory here called Cube API server so now there are actually logs of the so now there are actually logs of the so now there are actually logs of the API server stored in my system so I'm API server stored in my system so I'm API server stored in my system so I'm going to go into Cube system Cube API server and let's cat that log see okay server and let's cat that log see okay unknown flag authorization unknown flag authorization unknown flag authorization modus so they have set us up with with modus so they have set us up with with modus so they have set us up with with some uh unknown flag so I'm going to some uh unknown flag so I'm going to some uh unknown flag so I'm going to create a new window again I'm just going create a new window again I'm just going create a new window again I'm just going to go to CD at C manifests to go to CD at C manifests to go to CD at C manifests kubernetes kubernetes kubernetes manifests and then VM Cube API manifests and then VM Cube API manifests and then VM Cube API server and authorization server and authorization server and authorization modus let's check out the docs what that modus let's check out the docs what that modus let's check out the docs what that should should should be AP be AP be AP server B

  7. audits here author audits here author authorization mode authorization mode authorization mode not modus here is the right flag so not modus here is the right flag so not modus here is the right flag so we're going to get back we're going to get back we're going to get back and change this to mode quit that and then let's see if the mode quit that and then let's see if the API server restarts now uh it's running for a few seconds now uh it's running for a few seconds the the container is running the the container is running the the container is running now so let's see okay the connection is still it is see okay the connection is still it is still crashing but we're getting still crashing but we're getting still crashing but we're getting somewhere so let's go into Cube somewhere so let's go into Cube somewhere so let's go into Cube system Cube API server control plane system Cube API server control plane system Cube API server control plane Cube API Cube API Cube API server cut the last log here we see okay error while log here we see okay error while dialing 2,300 connection dialing 2,300 connection dialing 2,300 connection refused let's check out what it's trying refused let's check out what it's trying refused let's check out what it's trying to reach then to reach then to reach then 2300 at CD servers so it's trying to 2300 at CD servers so it's trying to 2300 at CD servers so it's trying to reach at CD at

  8. reach at CD at reach at CD at 2,300 2,300 2,300 so let's see what the atcd port is by so let's see what the atcd port is by so let's see what the atcd port is by checking out at cd. checking out at cd. checking out at cd. yo and here we see advertise client URL yo and here we see advertise client URL yo and here we see advertise client URL at at at 2379 2379 2379 2379 2379 2379 so at CD servers at so at CD servers at so at CD servers at [Music] restarted hey I'm can get get resources restarted hey I'm can get get resources in the default namespace so the API in the default namespace so the API in the default namespace so the API server is up and server is up and server is up and running so now if I check it it should U running so now if I check it it should U running so now if I check it it should U finish the finish the finish the scenario yay validation successful so scenario yay validation successful so scenario yay validation successful so successfully fixed a misconfigured API successfully fixed a misconfigured API successfully fixed a misconfigured API server that was fun that was fun okay now the next fun that was fun okay now the next scenario that I wanted to scenario that I wanted to scenario that I wanted to do um I have this note or in my settle do um I have this note or in my settle do um I have this note or in my settle cast cast cast about killer Koda

  9. about killer Koda about killer Koda no no no cks and then cks scenarios to cks and then cks scenarios to cks and then cks scenarios to repeat at CD encryption that's also a repeat at CD encryption that's also a repeat at CD encryption that's also a I'm going to repeat that one too just to I'm going to repeat that one too just to I'm going to repeat that one too just to get get get everything in the fingers as we say in everything in the fingers as we say in everything in the fingers as we say in Dutch back to the scenarios and let's do Dutch back to the scenarios and let's do Dutch back to the scenarios and let's do the at CD all right create an encryption all right create an encryption configuration file at ATC kubernetes EC configuration file at ATC kubernetes EC configuration file at ATC kubernetes EC yl and make at CD use yl and make at CD use yl and make at CD use it it it so in the docs I'm going to search for so in the docs I'm going to search for so in the docs I'm going to search for encryption encryption encryption [Music] [Music] [Music] configuration and here we are at configuration and here we are at configuration and here we are at encrypting confidential data at encrypting confidential data at encrypting confidential data at rest all right so here here's an rest all right so here here's an rest all right so here here's an encryption configuration file an example encryption configuration file an example encryption configuration file an example of of of it so I believe there is a smaller one it so I believe there is a smaller one it so I believe there is a smaller one yeah here this is a nice small one so yeah here this is a nice small one so yeah here this is a nice small one so I'm going to take this I'm going to take this I'm going to take this one one one copy one provider should be of type ascg copy one provider should be of type ascg copy one provider should be of type ascg cm and with the password this is very cm and with the password this is very cm and with the password this is very sack sack sack so let's go and uh

  10. he he uh let's see kubernetes ET CD um I have to make the directory so CD um I have to make the directory so let's just CD into there CD at C let's just CD into there CD at C let's just CD into there CD at C kubernetes there's no atcd directory so kubernetes there's no atcd directory so kubernetes there's no atcd directory so make their make their make their atcd and then Vim ec. atcd and then Vim ec. atcd and then Vim ec. yaml so here we have an encryption yaml so here we have an encryption yaml so here we have an encryption configuration and configuration and configuration and all new Secrets should be encrypted all new Secrets should be encrypted all new Secrets should be encrypted using this one so it's just going to be using this one so it's just going to be using this one so it's just going to be Secrets Secrets Secrets as a e s GCM we're going to have key1 and then a GCM we're going to have key1 and then a secret here and it's a base 64 encoded secret here and it's a base 64 encoded secret here and it's a base 64 encoded secret and this is the fallback secret and this is the fallback secret and this is the fallback one and I forgot to do TMO and then set- one and I forgot to do TMO and then set- one and I forgot to do TMO and then set- oovi so going to do do that now again oovi so going to do do that now again oovi so going to do do that now again I'm going to go into I'm going to go into I'm going to go into my CD directory here oh CD at here oh CD at CD here is my encryption configuration CD here is my encryption configuration CD here is my encryption configuration and I need to create a and I need to create a and I need to create a key so one provider should be of type key so one provider should be of type key so one provider should be of type with password this is very sack so what with password this is very sack so what with password this is very sack so what we do and I I remember this you have to

  11. we do and I I remember this you have to we do and I I remember this you have to Echo with the flag n to remove the new Echo with the flag n to remove the new Echo with the flag n to remove the new line character so it's Echo n and then line character so it's Echo n and then line character so it's Echo n and then this is very this is very this is very SEC pipe that to base SEC pipe that to base SEC pipe that to base 64 here is our secret 64 here is our secret 64 here is our secret string and and paste paste paste paste that in here we paste that in here we paste that in here we go this should be our encryption and create an encryption configuration and create an encryption configuration file at EC and make at CD use file at EC and make at CD use file at EC and make at CD use it okay um how was that again is it okay um how was that again is it okay um how was that again is that use the that use the that use the [Music] [Music] [Music] new oh yeah you have to you have to add new oh yeah you have to you have to add new oh yeah you have to you have to add it in the cube API server here we go so that is similar to here encryption go so that is similar to here encryption provider config this is the line that we provider config this is the line that we provider config this is the line that we need to need to need to add add add copy copy copy [Music] [Music] [Music] so opening a new window here and so opening a new window here and so opening a new window here and and and and cdsc kubernetes

  12. manifests open the cube API server and manifests open the cube API server and is there any configuration already already um doesn't seem like it this is the flag um doesn't seem like it this is the flag um doesn't seem like it this is the flag that we're going to add encryption provider provider encryption no there's only this flag encryption no there's only this flag encryption no there's only this flag here so it's here so it's here so it's okay and then we're going to do Etsy okay and then we're going to do Etsy okay and then we're going to do Etsy kubernetes etcd EC yo all right and now I will I might have yo all right and now I will I might have to restart my API server let's to restart my API server let's to restart my API server let's see oh it is restart St in now see oh it is restart St in now see oh it is restart St in now so C watch and one c c LPS is the cube API server yeah it is LPS is the cube API server yeah it is now it just now it just now it just disappeared so it should restart any problem

  13. problem CD bar log bar log hold Cube system Cube API hold Cube system Cube API hold Cube system Cube API server uh open Etc kubernetes at CD no such uh open Etc kubernetes at CD no such file my head is covering it but it's file my head is covering it but it's file my head is covering it but it's saying no such file or here error opening encryption provider here error opening encryption provider confir configuration confir configuration confir configuration file in ety kubernetes etcd ec. yo no file in ety kubernetes etcd ec. yo no file in ety kubernetes etcd ec. yo no such file or directory that's such file or directory that's such file or directory that's interesting because I mean at CD kubernetes because I mean at CD kubernetes at I mean at C kubernetes at CD at C kubernetes at CD and then I have CD at C kubernetes at CD and then I have ec.

  14. ec. ec. yo no such file or D directory what the saying saying what okay let's check the docs encrypt generate the key that's docs encrypt generate the key that's what I've what I've what I've done write an encryption configuration done write an encryption configuration done write an encryption configuration file that I've done use the new file that I've done use the new file that I've done use the new configuration configuration configuration file you need to mount the oh of course file you need to mount the oh of course file you need to mount the oh of course you will need to mount the new you will need to mount the new you will need to mount the new encryption config file to the cube API encryption config file to the cube API encryption config file to the cube API server static pod I'm such an idiot I server static pod I'm such an idiot I server static pod I'm such an idiot I can't just tell oh you have to just look can't just tell oh you have to just look can't just tell oh you have to just look at the control playe Mr pod you just at the control playe Mr pod you just at the control playe Mr pod you just have to mount the entire control plane have to mount the entire control plane have to mount the entire control plane file file file system what an idiot I am oh oh well system what an idiot I am oh oh well system what an idiot I am oh oh well luckily it is I had this direction in luckily it is I had this direction in luckily it is I had this direction in the docs you need to mount the new the docs you need to mount the new the docs you need to mount the new encryption config file encryption config file encryption config file so what a donkey so okay let's go so what a donkey so okay let's go so what a donkey so okay let's go back and back and back and now I need to let's see close see close this

  15. CD manifest CD manifest here MIM Cube API server. yaml all right here MIM Cube API server. yaml all right here MIM Cube API server. yaml all right so this is the path and now I need to so this is the path and now I need to so this is the path and now I need to mount that path obviously viously so mount that path obviously viously so mount that path obviously viously so here we here we here we see all of these volumes I'm just going see all of these volumes I'm just going see all of these volumes I'm just going to copy one of the volumes add it to copy one of the volumes add it to copy one of the volumes add it here this is the path at kuet at path at kuet at CD that's the directory that I'm mounting and I'm going to name that at mounting and I'm going to name that at CD EC and EC and then the volume Mount is going to path just the path just the same at CD and then the name is at CD EC EC so now it's not just going to restart I so now it's not just going to restart I so now it's not just going to restart I actually have to move the Manifest file actually have to move the Manifest file actually have to move the Manifest file away for a little bit so move Cube API away for a little bit so move Cube API away for a little bit so move Cube API server to the directory below okay Cube API server is still

  16. okay Cube API server is still [Music] [Music] [Music] running even though I've removed the running even though I've removed the running even though I've removed the manifests interestingly interestingly all right the API server is gone all right the API server is gone all right the API server is gone [Music] [Music] [Music] now and if I now and if I now and if I [Music] now um move now um move it back to the Manifest directory now it back to the Manifest directory now it back to the Manifest directory now the API server should restart and I the API server should restart and I the API server should restart and I should see it coming back with uh the encryption configuration so uh the encryption configuration so watch watch watch N1 C N1 C N1 C CPS CBE API server is back up okay get up okay get pods all right the API server Cube API pods all right the API server Cube API pods all right the API server Cube API server is server is server is running and it has the encryption running and it has the encryption running and it has the encryption configuration so now I should be able to configuration so now I should be able to configuration so now I should be able to just um check the scenario it because it just um check the scenario it because it just um check the scenario it because it should be solved now yes and the should be solved now yes and the should be solved now yes and the validation was successful validation was successful validation was successful okay up next we need to encrypt all

  17. okay up next we need to encrypt all okay up next we need to encrypt all secrets oh yeah um yeah that's yeah yeah yeah here this is the command there's a yeah here this is the command there's a yeah here this is the command there's a oneliner where you can just get all oneliner where you can just get all oneliner where you can just get all secrets and then replace it it's just secrets and then replace it it's just secrets and then replace it it's just here in the doc super here in the doc super here in the doc super handy so just going to steal that and handy so just going to steal that and handy so just going to steal that and encrypt all existing secrets in encrypt all existing secrets in encrypt all existing secrets in namespace one using the new secret namespace one using the new secret namespace one using the new secret provider so so um this is the um this is the um this is the command so K get Secrets n one command so K get Secrets n one command so K get Secrets n one Ojon and then K replace F Dash okay so now those get replaced and Dash okay so now those get replaced and just to see to show you what's happening just to see to show you what's happening just to see to show you what's happening if i k get if i k get if i k get secret secret secret N2 Secret one o N2 Secret one o N2 Secret one o yl here we see that it is

  18. yl here we see that it is yl here we see that it is encrypted it has a value here but this encrypted it has a value here but this encrypted it has a value here but this is the the the value of secret one is the the the value of secret one is the the the value of secret one now but if I run this command and encrypt all of the secrets command and encrypt all of the secrets in namespace 2 again and replace them in namespace 2 again and replace them in namespace 2 again and replace them with the new encryption with the new encryption with the new encryption configuration now they are replaced and configuration now they are replaced and configuration now they are replaced and if I now get the secret one from if I now get the secret one from if I now get the secret one from namespace namespace namespace two it has the same oh yes it's not two it has the same oh yes it's not two it has the same oh yes it's not encrypting the it's not actually encrypting the it's not actually encrypting the it's not actually encrypting the secret in the namespace encrypting the secret in the namespace encrypting the secret in the namespace it's encrypting it in at CD that's what it's encrypting it in at CD that's what it's encrypting it in at CD that's what it's doing so by replacing the secret it's doing so by replacing the secret it's doing so by replacing the secret I'm I'm encrypting it in at so going back and then I'm going to so going back and then I'm going to do the last one in nam space one in nam space three they are also replaced check it three they are also replaced check it three they are also replaced check it and it has validated and it has validated and it has validated successfully awesome and the next awesome and the next one so those were ones that I wanted to one so those were ones that I wanted to one so those were ones that I wanted to repeat those were good and every day I

  19. repeat those were good and every day I repeat those were good and every day I have to do something with rback or have to do something with rback or have to do something with rback or network policies I haven't done rback network policies I haven't done rback network policies I haven't done rback for a little bit so I should do an rback for a little bit so I should do an rback for a little bit so I should do an rback scenario too and after that I want to scenario too and after that I want to scenario too and after that I want to get to some fun stuff uh by um reducing get to some fun stuff uh by um reducing get to some fun stuff uh by um reducing the footprint of the footprint of the footprint of containers but let's just do one rback containers but let's just do one rback containers but let's just do one rback scenario let's see have I done all of scenario let's see have I done all of scenario let's see have I done all of the rback ones the rback ones the rback ones for for for cks yeah service account user permissions I've done these maybe permissions I've done these maybe there's something in the cka that I there's something in the cka that I there's something in the cka that I haven't done yet yet uh wow 70 scenarios for cka there must uh wow 70 scenarios for cka there must uh wow 70 scenarios for cka there must be some R back be some R back be some R back here nothing what I thought AR arbec used to be part of I thought AR arbec used to be part of the the the cka here arback service account cka here arback service account cka here arback service account permissions and user permissions well permissions and user permissions well permissions and user permissions well let's do a service account permissions permissions start we have existing namespaces ns1 start we have existing namespaces ns1 start we have existing namespaces ns1 and ns2 create a service account and ns2 create a service account and ns2 create a service account pipeline in both pipeline in both pipeline in both namespaces it should be allowed to view namespaces it should be allowed to view namespaces it should be allowed to view almost everything in the whole cluster almost everything in the whole cluster almost everything in the whole cluster and you can use the default cluster roll and you can use the default cluster roll and you can use the default cluster roll view for

  20. view for view for this they should be allowed to create this they should be allowed to create this they should be allowed to create and delete deployments in their namespace namespace okay okay let's check it spaces okay t-x set- spaces okay t-x set- OVI K OVI K OVI K create um s create um s create um s pipeline n ns1 created in the first name pipeline n ns1 created in the first name pipeline n ns1 created in the first name space and then I'm going to create it in space and then I'm going to create it in space and then I'm going to create it in the namespace number the namespace number the namespace number two these SAS should be allowed to view two these SAS should be allowed to view two these SAS should be allowed to view almost everything in the whole cluster almost everything in the whole cluster almost everything in the whole cluster you can use the default cluster roll you can use the default cluster roll you can use the default cluster roll view for this so we're going to create a view for this so we're going to create a view for this so we're going to create a roll binding roll binding roll binding okay create roll binding output the help and split the binding output the help and split the screen because here I see a very nice screen because here I see a very nice screen because here I see a very nice little little little um Whatchamacallit example here so K um Whatchamacallit example here so K um Whatchamacallit example here so K create R binding and then it will be ns1 cluster roll is ns1 cluster roll is View and and then the View and and then the View and and then the service account is

  21. it and we need to create that in the it and we need to create that in the namespace namespace namespace ns1 yeah so K get Ro binding n ns1 yeah so K get Ro binding n ns1 yeah so K get Ro binding n ns1 ns1 o ns1 ns1 o ns1 ns1 o yo so in namespace ns1 we have a cluster yo so in namespace ns1 we have a cluster yo so in namespace ns1 we have a cluster roll view bound to service account roll view bound to service account roll view bound to service account pipeline okay so that worked that must pipeline okay so that worked that must pipeline okay so that worked that must be it okay set- OVI here too then I'm going it okay set- OVI here too then I'm going to do the same one to do the same one to do the same one for ns2 for ns2 for ns2 [Music] ns2 and if I now get the RO ns2 and if I now get the RO binding to binding to binding to two we see that too so the cluster role two we see that too so the cluster role two we see that too so the cluster role is successfully bound to that service is successfully bound to that service is successfully bound to that service account next these SAS should be allowed account next these SAS should be allowed account next these SAS should be allowed to create and delete deployments in to create and delete deployments in to create and delete deployments in their namespace so I'm going to create a a custom roll so I'm going to create a a custom roll for this this and let's see just checking the screen and let's see just checking the screen and let's see just checking the screen the stream screen here for a bit but um

  22. the stream screen here for a bit but um the stream screen here for a bit but um we're good then I'm going to switch to we're good then I'm going to switch to we're good then I'm going to switch to the window up here and then it's uh K the window up here and then it's uh K the window up here and then it's uh K create roll help and now I see this create roll help and now I see this create roll help and now I see this command here go command here go command here go [Music] ns1 ns1 D verb delete resource delete resource equals namespace so if i k get namespace so if i k get Roll n Roll n Roll n ns1 ns1 ns1 ns1 ns1 ns1 [Music] [Music] [Music] d d d o then I see API Group apps resources o then I see API Group apps resources o then I see API Group apps resources deployments and create and delete so deployments and create and delete so deployments and create and delete so that works and then I'm going to create that works and then I'm going to create that works and then I'm going to create the the the role for NS 2D as well that's create and now it's to well that's create and now it's to create a ro binding create a ro binding create a ro binding again so okay create Ro binding

  23. h k create R h k create R binding ns1 D Ro is ns1 D Ro is ns1 D service account account is one and then K get roll one and then K get roll binding n ns1 ns1 d o y here we see that the roll ns1 ns1 d o y here we see that the roll ns1 D was bound to the service account ns1 D was bound to the service account ns1 D was bound to the service account pipeline so that should be pipeline so that should be pipeline so that should be it and then create it for the Nam space it and then create it for the Nam space it and then create it for the Nam space number two as well oops well oops uh service account ns2 okay ns2 okay delete Ro accidentally no wait k get R binding n

  24. accidentally no wait k get R binding n ns2 ns2 ns2 I have to delete that one so K delete I have to delete that one so K delete I have to delete that one so K delete roll binding n ns2 ns2 roll binding n ns2 ns2 roll binding n ns2 ns2 [Music] [Music] [Music] d okay here we go again because I made a d okay here we go again because I made a d okay here we go again because I made a mistake create Ro binding mistake create Ro binding mistake create Ro binding NSD service account NSD service account NSD service account NS 2 pipeline here we go now it should NS 2 pipeline here we go now it should NS 2 pipeline here we go now it should be be be correct so let's try some verifications correct so let's try some verifications correct so let's try some verifications here here here K off can I and then help uh K off can help uh K off can I I I get um f in the namespace cube system yes they can the namespace cube system yes they can get pods in the cube system names space get pods in the cube system names space get pods in the cube system names space space because they have the cluster space because they have the cluster space because they have the cluster viewer viewer viewer role now if I role now if I role now if I now ask can I delete pods in the cube now ask can I delete pods in the cube now ask can I delete pods in the cube system Nam space Oh wait yeah I'm saying can I but space Oh wait yeah I'm saying can I but of course I need of course I need of course I need to um

  25. to um to um like I'm now saying can I as the user do like I'm now saying can I as the user do like I'm now saying can I as the user do this but I have to of this but I have to of this but I have to of course um specify that I'm the service course um specify that I'm the service course um specify that I'm the service account so let's pipe that to less and account so let's pipe that to less and account so let's pipe that to less and how do how do how do I yeah here we go as system service I yeah here we go as system service I yeah here we go as system service account Dev Fu so here we go account Dev Fu so here we go account Dev Fu so here we go again can I delete pod in namespace Cube system system as system service as system service as system service [Music] account account [Music] [Music] [Music] Cube Cube Cube um ns1 pipeline here we go as the system ns1 pipeline here we go as the system service account from namespace ns1 named service account from namespace ns1 named service account from namespace ns1 named pipeline no I cannot delete pods in the pipeline no I cannot delete pods in the pipeline no I cannot delete pods in the cube system names space but can I get cube system names space but can I get cube system names space but can I get them them them no can I view them view is another known them view is another known verb can I list verb can I list verb can I list them no okay so is that done correctly then K no okay so is that done correctly then K get R binding n

  26. ns1 oh wait I need to create a cluster ns1 oh wait I need to create a cluster roll roll roll binding of binding of binding of course they should be allowed to view course they should be allowed to view course they should be allowed to view almost everything in the whole almost everything in the whole almost everything in the whole cluster yeah so okay create cluster roll yeah so okay create cluster roll binding that's what I need to binding that's what I need to binding that's what I need to do do do um can I just edit this okay edit roll binding can I just turn this into binding can I just turn this into cluster roll binding binding error nope can't do that so I have to K error nope can't do that so I have to K error nope can't do that so I have to K create oh maybe I have the command create oh maybe I have the command create oh maybe I have the command here uh roll here uh roll here uh roll [Music] let's let's see um roll see um roll see um roll binding okay create

  27. deployments deployments here okay here okay here okay create cluster roll binding ns2 cluster create cluster roll binding ns2 cluster create cluster roll binding ns2 cluster roll view yes okay and now change this one to view yes okay and now change this one to one and this one to yeah this is why I need more practice yeah this is why I need more practice with this because I'm I'm stumbling with this because I'm I'm stumbling with this because I'm I'm stumbling around too much still I need to get I around too much still I need to get I around too much still I need to get I need to do much more practice with this need to do much more practice with this need to do much more practice with this I realize ns2 ns2 okay cluster roll

  28. binding okay create this binding okay create this [Music] [Music] [Music] one this one this one this one one one and this one okay now it should be in and this one okay now it should be in and this one okay now it should be in both so going back back can I list pods in the cube system s can I list pods in the cube system s can I list pods in the cube system s Service account ns1 Service account ns1 Service account ns1 pipeline yes ha now it pipeline yes ha now it pipeline yes ha now it worked all right and if I do it as worked all right and if I do it as worked all right and if I do it as [Music] ns2 yes but can I delete pods in the ns2 yes but can I delete pods in the cube system namespace no I cannot cube system namespace no I cannot cube system namespace no I cannot can I can I can I delete delete delete deployments in deployments in deployments in the ns2 name yes I can can I do it in the ns2 name yes I can can I do it in the ns2 name yes I can can I do it in the ns1 name the ns1 name the ns1 name space no I cannot okay I think I've space no I cannot okay I think I've space no I cannot okay I think I've solved it now I think I've solved solved it now I think I've solved solved it now I think I've solved it let's check it let's check it let's check it yes nice all it yes nice all it yes nice all right at least I managed to figure it right at least I managed to figure it right at least I managed to figure it out but I'm taking too much time still I out but I'm taking too much time still I out but I'm taking too much time still I need much more practice for these rback need much more practice for these rback need much more practice for these rback scenarios much more practice because scenarios much more practice because scenarios much more practice because this is too much stumbling around how is the Pomodoro 10 minutes

  29. around how is the Pomodoro 10 minutes left okay well let's do another p uh left okay well let's do another p uh left okay well let's do another p uh let's do let's do let's do another roll back scenario and then another roll back scenario and then another roll back scenario and then after the Pomodoro is done I'm going to after the Pomodoro is done I'm going to after the Pomodoro is done I'm going to do some container footprint work work so I am going to go back to the scenarios scenarios check check check scenarios and in the cka there is scenarios and in the cka there is scenarios and in the cka there is another rback user another rback user another rback user permissions this is one is going to be permissions this is one is going to be permissions this is one is going to be about users let's check this one let's check this one out there's an existing namespace out there's an existing namespace out there's an existing namespace applications and user smoke should be applications and user smoke should be applications and user smoke should be allowed to create and delete pods blah allowed to create and delete pods blah allowed to create and delete pods blah blah blah should have view blah blah should have view blah blah should have view permissions in all Spa name spaces but permissions in all Spa name spaces but permissions in all Spa name spaces but not in Cube not in Cube not in Cube system and verify everything using Cube system and verify everything using Cube system and verify everything using Cube CTL or can CTL or can CTL or can I oh wait I remember this I've done this I oh wait I remember this I've done this I oh wait I remember this I've done this scenario before but this is actually a scenario before but this is actually a scenario before but this is actually a trick question because you trick question because you trick question because you can't um negatively assign role can't um negatively assign role can't um negatively assign role assignments I'm pretty sure about that assignments I'm pretty sure about that assignments I'm pretty sure about that so for so for so for now I'm going to ignore this one okay um user smoke should be allowed

  30. one okay um user smoke should be allowed to create and delete pods deployments to create and delete pods deployments to create and delete pods deployments and stateful sets in namespace and stateful sets in namespace and stateful sets in namespace applications open t-mo set- applications open t-mo set- applications open t-mo set- OVI K create roll DH open new one set- OVI K create roll DH open new one set- OVI K create roll DH open new one set- OVI OVI OVI and now we're going to K create roll roll smoke and then we are going smoke and then we are going smoke and then we are going [Music] [Music] [Music] to do verb equal to do verb equal to do verb equal create create create delete resource delete resource delete resource is POD is POD is POD deployment and state full set and it's going to be in the names set and it's going to be in the names space space space applications K get Roll n applications applications K get Roll n applications applications K get Roll n applications smoke o smoke o smoke o yaml resources yaml resources yaml resources pods deployment stateful sets create and pods deployment stateful sets create and pods deployment stateful sets create and delete so that role seems correct to delete so that role seems correct to delete so that role seems correct to me and then we are going to clear this me and then we are going to clear this me and then we are going to clear this and and and then

  31. then then uh K create Ro uh K create Ro uh K create Ro binding help K create roll binding help K create roll binding help K create roll binding binding binding smoke roll equals smoke and then user smoke roll equals smoke and then user smoke roll equals smoke and then user equals equals equals smoke in the namespace application application applications so K off can I uh I uh create create create pod as pod as pod as what what was it K off can um s um s as smoke just like that can I off create as smoke just like that can I off create as smoke just like that can I off create pod as smoke in the pod as smoke in the pod as smoke in the namespace cube system namespace cube system namespace cube system no in namespace no in namespace no in namespace applications yes okay so that applications yes okay so that applications yes okay so that worked so I think this is already it worked so I think this is already it worked so I think this is already it because this is a bit of a trick because this is a bit of a trick because this is a bit of a trick question I believe but so I'm just going

  32. question I believe but so I'm just going question I believe but so I'm just going to check it no the validation failed to check it no the validation failed to check it no the validation failed okay well user smoke should have view okay well user smoke should have view okay well user smoke should have view permissions like the permissions of the permissions like the permissions of the permissions like the permissions of the default cluster Ro in all Nam default cluster Ro in all Nam default cluster Ro in all Nam spaces but not in Cube spaces but not in Cube spaces but not in Cube system oh now I remember yeah you have system oh now I remember yeah you have system oh now I remember yeah you have to actually create it in all namespaces to actually create it in all namespaces to actually create it in all namespaces manually because you can't do like a manually because you can't do like a manually because you can't do like a roll with a scope of some name Nam roll with a scope of some name Nam roll with a scope of some name Nam spaces and then exclude some of them now spaces and then exclude some of them now spaces and then exclude some of them now remember you can't do that I'll actually remember you can't do that I'll actually remember you can't do that I'll actually have to create a rule for every names have to create a rule for every names have to create a rule for every names space so K get n space so K get n space so K get n s s s here um the RO already exists it's a here um the RO already exists it's a here um the RO already exists it's a cluster Ral view so all I need to do is cluster Ral view so all I need to do is cluster Ral view so all I need to do is create a ro create a ro create a ro binding for a user smoke in every binding for a user smoke in every binding for a user smoke in every namespace namespace namespace so that what I'm going to do is I'm so that what I'm going to do is I'm so that what I'm going to do is I'm going to K create going to K create going to K create cluster roll binding help okay create cluster roll binding help okay create cluster roll binding smoke cluster roll equals smoke cluster roll equals smoke cluster roll equals [Music] [Music] [Music] viewer no view viewer no view viewer no view view and then the user is view and then the user is view and then the user is smoke and then the Nam space is let's

  33. smoke and then the Nam space is let's smoke and then the Nam space is let's start with default yeah so K get NS default yeah so K get NS I have to create in I have to create in I have to create in default in Cube node lease no I should not create a cluster lease no I should not create a cluster roll binding it has to be a roll binding roll binding it has to be a roll binding roll binding it has to be a roll binding in every uh yes oopsie so okay delete in every uh yes oopsie so okay delete in every uh yes oopsie so okay delete cluster roll cluster roll cluster roll binding smoke because yeah cluster roll binding smoke because yeah cluster roll binding smoke because yeah cluster roll bindings are not namespaced what a bindings are not namespaced what a bindings are not namespaced what a donkey again create roll donkey again create roll donkey again create roll binding smoke cluster roll binding smoke cluster roll binding smoke cluster roll view yeah this should be view yeah this should be view yeah this should be it so Cube node it so Cube node it so Cube node lease default and then we're going to do it default and then we're going to do it for names for names for names space Cube space Cube space Cube public can I do a comma separated storage no you can't do that okay CU storage no you can't do that okay CU public and I'm going to create it for public and I'm going to create it for public and I'm going to create it for the the the namespace local path storage okay so now namespace local path storage okay so now namespace local path storage okay so now I've created a r binding to the cluster

  34. I've created a r binding to the cluster I've created a r binding to the cluster roll view in every names space and now I roll view in every names space and now I roll view in every names space and now I should check and the validation failed view has to be cluster roll View and view has to be cluster roll View and then the user smokes then the user smokes then the user smokes and that is in all Nam spaces now oh and that is in all Nam spaces now oh and that is in all Nam spaces now oh wait I didn't create it in applications wait I didn't create it in applications wait I didn't create it in applications maybe that's maybe that's maybe that's it and applications that name already exists applications that name already exists because I use that for the other Ro because I use that for the other Ro because I use that for the other Ro binding okay so now we should do binding okay so now we should do binding okay so now we should do it yes yay validation successful

  35. it yes yay validation successful it yes yay validation successful so I I had forgotten to do it in the so I I had forgotten to do it in the so I I had forgotten to do it in the applications name space that was the applications name space that was the applications name space that was the problem problem problem here here here um but what what the doubt that I had is um but what what the doubt that I had is um but what what the doubt that I had is this let's check the the the hints here this let's check the the the hints here this let's check the the the hints here you have arback you have arback you have arback info info info [Music] [Music] [Music] and uh uh yeah here it yeah here it yeah here it says as of now it's not possible to says as of now it's not possible to says as of now it's not possible to create deny rback in kubernetes so we create deny rback in kubernetes so we create deny rback in kubernetes so we allow for all other name allow for all other name allow for all other name spaces so you actually have to do it for spaces so you actually have to do it for spaces so you actually have to do it for every name space you have to create it every name space you have to create it every name space you have to create it because he should not have the cluster because he should not have the cluster because he should not have the cluster all in the cube system Nam space so you all in the cube system Nam space so you all in the cube system Nam space so you have to go and use it for every every have to go and use it for every every have to go and use it for every every Nam space hi from Copenhagen ah hello I work space hi from Copenhagen ah hello I work for a uh Danish based company for a uh Danish based company for a uh Danish based company currently I speak Norwegian but no currently I speak Norwegian but no currently I speak Norwegian but no Danish but it's a I work for a company Danish but it's a I work for a company Danish but it's a I work for a company that's um started a a an office in the that's um started a a an office in the that's um started a a an office in the Netherlands so that's cool to have Netherlands so that's cool to have Netherlands so that's cool to have another someone from Copenhagen another someone from Copenhagen another someone from Copenhagen here can it be K create R binding and here can it be K create R binding and here can it be K create R binding and all no because it doesn't have to be in all no because it doesn't have to be in all no because it doesn't have to be in all name it shouldn't be in all name all name it shouldn't be in all name all name it shouldn't be in all name spaces it has to be all name space is spaces it has to be all name space is spaces it has to be all name space is accept Cube system so that was the

  36. accept Cube system so that was the accept Cube system so that was the problem but um Now it problem but um Now it problem but um Now it worked so we worked so we worked so we are we're golden all right my Pomodoro Timer has ended so I'm right my Pomodoro Timer has ended so I'm just going to take a quick break maybe 5 just going to take a quick break maybe 5 just going to take a quick break maybe 5 10 minutes or so and then I'm going to 10 minutes or so and then I'm going to 10 minutes or so and then I'm going to work on some Docker work on some Docker work on some Docker files so uh let's see Pomo start and files so uh let's see Pomo start and files so uh let's see Pomo start and [Music] [Music] [Music] then start break on a break yeah I probably won't break on a break yeah I probably won't take the full 10 minutes maybe five8 take the full 10 minutes maybe five8 take the full 10 minutes maybe five8 minutes or so but um I'm just going to minutes or so but um I'm just going to minutes or so but um I'm just going to stretch my legs and I'll be right okay getting everything back in order

  37. okay getting everything back in order here and just fixing up my set up a here and just fixing up my set up a here and just fixing up my set up a little bit we round let's see round let's see okay where can I get that Pomodoro okay where can I get that Pomodoro okay where can I get that Pomodoro Timer um the Pomodoro Timer the Timer um the Pomodoro Timer the Timer um the Pomodoro Timer the configuration for for it is in the dot configuration for for it is in the dot configuration for for it is in the dot files files files repo but the Pomo itself that is created repo but the Pomo itself that is created repo but the Pomo itself that is created by the one and only rwx Rob Rob so it is a go binary and you can get it so it is a go binary and you can get it so it is a go binary and you can get it for yourself um it's in rwx Rob Pomo here it's a go binary that you can Pomo here it's a go binary that you can install and then if you look in my DOT install and then if you look in my DOT install and then if you look in my DOT files repo you can see the tmox files repo you can see the tmox files repo you can see the tmox configuration for it how I've set it configuration for it how I've set it configuration for it how I've set it up so now I've done my my daily practice up so now I've done my my daily practice up so now I've done my my daily practice with with with arback and now it's time for some arback and now it's time for some arback and now it's time for some container image container image container image footprint I just finished that bit of footprint I just finished that bit of footprint I just finished that bit of the

  38. the the course course course and and and yeah here image footprint and now it was yeah here image footprint and now it was yeah here image footprint and now it was instructing me to he was instructing me instructing me to he was instructing me instructing me to he was instructing me to go to the scenarios so we're going to to go to the scenarios so we're going to to go to the scenarios so we're going to try those and I have an image of myself try those and I have an image of myself try those and I have an image of myself that I want to tune a bit so let's check that I want to tune a bit so let's check that I want to tune a bit so let's check it out container image footprint it out container image footprint it out container image footprint [Music] [Music] [Music] user and we have a user and we have a user and we have a queue oh that's because I have this one queue oh that's because I have this one queue oh that's because I have this one still open still open still open so delete that so delete that so delete that one go let's go let's see there's a given Docker file under see there's a given Docker file under see there's a given Docker file under opt KS Docker file build an image named opt KS Docker file build an image named opt KS Docker file build an image named base image from the docker file and run base image from the docker file and run base image from the docker file and run a container named C1 from that a container named C1 from that a container named C1 from that image check on which user the Sleep image check on which user the Sleep image check on which user the Sleep process is running inside the process is running inside the process is running inside the container sure so t-x set- container sure so t-x set- container sure so t-x set- oovi oovi oovi and we go to opt KS check out the docker KS check out the docker file all file all file all right so we see that it is it does a run right so we see that it is it does a run right so we see that it is it does a run add add add user so it's adding a user but it's not user so it's adding a user but it's not user so it's adding a user but it's not actually running as it yet but we can uh actually running as it yet but we can uh actually running as it yet but we can uh we can do Docker we can do Docker we can do Docker build T base

  39. building then Docker building then Docker run um um C1 it needs to be named C1 from the C1 it needs to be named C1 from the C1 it needs to be named C1 from the image and then base image this should image and then base image this should image and then base image this should be oh oh no Docker run base image and then name no Docker run base image and then name no Docker run base image and then name C1 that's that's probably yeah assign a name to The Container what yeah assign a name to The Container what the hell Docker run name hell Docker run name C1 base image that's taking a long image that's taking a long time oh of course because it is a sleep time oh of course because it is a sleep time oh of course because it is a sleep man so now it's it's actually running so man so now it's it's actually running so man so now it's it's actually running so I'm opening a new window if I Docker PS I'm opening a new window if I Docker PS I'm opening a new window if I Docker PS now I see the the image it's running and now I see the the image it's running and now I see the the image it's running and it's having a sleep command so it's just it's having a sleep command so it's just it's having a sleep command so it's just opening it has the terminal open I don't opening it has the terminal open I don't opening it has the terminal open I don't have it run in detached mode so it's

  40. have it run in detached mode so it's have it run in detached mode so it's just waiting for the Sleep command to just waiting for the Sleep command to just waiting for the Sleep command to finish finish which will take one day so finish finish which will take one day so finish finish which will take one day so if I now if I now if I now okay uh Docker exec exec [Music] [Music] [Music] it it it Dash or sh here we go then now I'm in the sh here we go then now I'm in the container and now we have to find out container and now we have to find out container and now we have to find out what user the sleep proess is running what user the sleep proess is running what user the sleep proess is running under so under so under so PSO grab PSO grab PSO grab sleep we see that the Sleep command is sleep we see that the Sleep command is sleep we see that the Sleep command is running as user running as user running as user rout rout rout check successful all right modify the check successful all right modify the check successful all right modify the docker file to run processes as user app docker file to run processes as user app docker file to run processes as user app user update the base image with your user update the base image with your user update the base image with your change and build a new container C2 from change and build a new container C2 from change and build a new container C2 from that that that image sure thing uh exit the container so Docker thing uh exit the container so Docker stop stop stop Docker Docker Docker PS Docker PS Docker PS Docker stop this container so that should free stop this container so that should free stop this container so that should free up the other shell

  41. again yep it's freed up again okay again yep it's freed up again okay so we are in up we are in up KS we have the docker file and then I KS we have the docker file and then I KS we have the docker file and then I believe is it's as simple as just believe is it's as simple as just believe is it's as simple as just running running running user app user like that I believe it's user app user like that I believe it's user app user like that I believe it's that then we're going to build it again okay so that is again okay so that is built and then we can do do dock ER built and then we can do do dock ER built and then we can do do dock ER run and then I'm going to do it in run and then I'm going to do it in run and then I'm going to do it in detach mode Docker run detach mode Docker run detach mode Docker run [Music] xac xac C2 shell shell [Music] [Music] [Music] C2 oh EXA it of course SE it here we go

  42. C2 oh EXA it of course SE it here we go C2 oh EXA it of course SE it here we go now we're on the shell and then PS out now we're on the shell and then PS out now we're on the shell and then PS out grab grab grab sleep it's now sleep it's now sleep it's now [Music] running running as app user yeah here we go I was I was as app user yeah here we go I was I was as app user yeah here we go I was I was confused by one but root user ID is zero confused by one but root user ID is zero confused by one but root user ID is zero of course so yes it's running as app of course so yes it's running as app of course so yes it's running as app user so it works user so it works user so it works so the scenario should be solved yeah so the scenario should be solved yeah so the scenario should be solved yeah and this validation is successful and this validation is successful and this validation is successful hooray now the next one scenarios here's scenarios here's scenarios the next one was container scenarios the next one was container scenarios the next one was container hardening so let's check out that hardening there is a Docker file at root hardening there is a Docker file at root image Docker file it's a simple image Docker file it's a simple image Docker file it's a simple container which tries to make a curl to container which tries to make a curl to container which tries to make a curl to an imaginary an imaginary an imaginary API use specific version for the base API use specific version for the base API use specific version for the base image remove layer caching issues with image remove layer caching issues with image remove layer caching issues with appg remove the hardcoded secret value ah pass it as an environment value ah pass it as an environment variable and make it impossible to pman

  43. um TMX set- um TMX set- OVI CD root OVI CD root OVI CD root image Vim Docker file what do we see ah image Vim Docker file what do we see ah image Vim Docker file what do we see ah from from from auntu okay we tag it to that okay we tag it to that version remove layer caching issues with version remove layer caching issues with version remove layer caching issues with apt get uh then I have to put this on one get uh then I have to put this on one line I believe up get update believe up get update and and and have get install curl and if curl and if [Music] [Music] [Music] URL that's the okay so I have to give it another okay so I have to give it another environment variable and token just give the token and then this token just give the token and then this should

  44. be be token token token right remove the hard code the secret right remove the hard code the secret right remove the hard code the secret value should be passed into the value should be passed into the value should be passed into the Container during runtime as an N Container during runtime as an N Container during runtime as an N variable variable variable token then make it impossible to pman token then make it impossible to pman token then make it impossible to pman exact Docker xac or cube CTL xac into exact Docker xac or cube CTL xac into exact Docker xac or cube CTL xac into the Container using the Container using the Container using bash um for that one I believe it bash um for that one I believe it bash um for that one I believe it is run RM RF bin run RM RF bin bash I think that's it it it potman build arguments okay arguments okay so what is that the default so what is that the default so what is that the default value value value okay okay so it's building it's kep okay so it's building it's kep [Music]

  45. updating updating okay do we have to run it or LS I have to try it LS I have to try it right let's tag it with uh Run Okay so that works bman run detached Run Okay so that works bman run detached Misha bman exac Misha bman exac Misha bman exac it Misha Bash bman Bash bman and yes and yes and yes yes oh it's not yes oh it's not yes oh it's not running oh yeah because the it just runs running oh yeah because the it just runs running oh yeah because the it just runs and then it's it closes well let's check and then it's it closes well let's check and then it's it closes well let's check it out if it it out if it it out if it works okay you solved the challenge it works okay you solved the challenge it works okay you solved the challenge it already works all right well that was already works all right well that was already works all right well that was easy easy easy great well what I what I next want to do great well what I what I next want to do great well what I what I next want to do is the other day I was doing this

  46. is the other day I was doing this is the other day I was doing this project in my GitHub so github.com Misha project in my GitHub so github.com Misha project in my GitHub so github.com Misha [Music] [Music] [Music] venberg check out my venberg check out my venberg check out my repositories and I have this repositories and I have this repositories and I have this um settle C and tracker this is a fun um settle C and tracker this is a fun um settle C and tracker this is a fun little project that I started last little project that I started last little project that I started last week this is a week this is a week this is a binary that checks out that that looks binary that checks out that that looks binary that checks out that that looks at the number number of notes in my zle at the number number of notes in my zle at the number number of notes in my zle cast and then pushes it to cast and then pushes it to cast and then pushes it to Prometheus so now in my grafana in my Prometheus so now in my grafana in my Prometheus so now in my grafana in my home lab I have this graph where it home lab I have this graph where it home lab I have this graph where it actually shows the amount of notes in my actually shows the amount of notes in my actually shows the amount of notes in my zle cast and and as it's zle cast and and as it's zle cast and and as it's growing so over the last s growing so over the last s growing so over the last s days I see that my zel cast notes have days I see that my zel cast notes have days I see that my zel cast notes have grown from grown from grown from 2,256 2,256 2,256 56 to 2 56 to 2 56 to 2 310 so that's quite a significant 310 so that's quite a significant 310 so that's quite a significant increase of notes in my increase of notes in my increase of notes in my zc and this information is very zc and this information is very zc and this information is very important to me so I'll show you the important to me so I'll show you the important to me so I'll show you the postrest cluster that's running this postrest cluster that's running this postrest cluster that's running this this is all running on my kubernetes this is all running on my kubernetes this is all running on my kubernetes home home home lab lab lab and my zcast and tracker and my zcast and tracker and my zcast and tracker database had a base backup to Azure so database had a base backup to Azure so database had a base backup to Azure so it's everything is is backed up to um to

  47. it's everything is is backed up to um to it's everything is is backed up to um to Azure blob storage and has been backed Azure blob storage and has been backed Azure blob storage and has been backed up 14 hours ago it's running with three up 14 hours ago it's running with three up 14 hours ago it's running with three replicas and interestingly it's replicas and interestingly it's replicas and interestingly it's utilizing its memory quite uh more than utilizing its memory quite uh more than utilizing its memory quite uh more than I expected so that's that's cool I might I expected so that's that's cool I might I expected so that's that's cool I might have to increase the me memory a little have to increase the me memory a little have to increase the me memory a little bit but the post cross cluster is uh bit but the post cross cluster is uh bit but the post cross cluster is uh looking very nice even for such a silly looking very nice even for such a silly looking very nice even for such a silly application application application and I wrote it in go so this is the go and I wrote it in go so this is the go and I wrote it in go so this is the go code it's just very simple it's code it's just very simple it's code it's just very simple it's uh has an init and it constructs a uh has an init and it constructs a uh has an init and it constructs a database um connection database um connection database um connection string and then it counts it it it string and then it counts it it it string and then it counts it it it serves an API that listens on slash serves an API that listens on slash serves an API that listens on slash count and what I then do is I have a count and what I then do is I have a count and what I then do is I have a cron tab I have a Chron cron tab I have a Chron cron tab I have a Chron job the kicks off the ZK count script job the kicks off the ZK count script job the kicks off the ZK count script that I that I that I have and then if I go to my scripts have and then if I go to my scripts have and then if I go to my scripts directory in my DOT files repo ZK directory in my DOT files repo ZK directory in my DOT files repo ZK count here is the count here is the count here is the script it's script it's script it's um it uh does a find command in my zcast um it uh does a find command in my zcast um it uh does a find command in my zcast and then counts the and then counts the and then counts the lines and then it pushes that to the API lines and then it pushes that to the API lines and then it pushes that to the API that's served by this go binary that I that's served by this go binary that I that's served by this go binary that I created and all of that is running in my

  48. created and all of that is running in my created and all of that is running in my kubernetes kubernetes kubernetes cluster in my home lab cluster in my home lab cluster in my home lab cluster and if I just switch to the cluster and if I just switch to the cluster and if I just switch to the zcast tracker zcast tracker zcast tracker repository here you see that I have it repository here you see that I have it repository here you see that I have it running in a running in a running in a pod and with three replicas of the pod and with three replicas of the pod and with three replicas of the database no less this is very important database no less this is very important database no less this is very important information to information to information to me and here is the running application me and here is the running application me and here is the running application now the thing is I created this thing now the thing is I created this thing now the thing is I created this thing with a Docker file with a Docker file with a Docker file uh is going to my repo here and then zle uh is going to my repo here and then zle uh is going to my repo here and then zle cast tracker I created tracker I created this Docker file but today I this Docker file but today I this Docker file but today I learned that I learned that I learned that I can can can uh oh okay I'm already doing it oh I uh oh okay I'm already doing it oh I uh oh okay I'm already doing it oh I forgot about forgot about forgot about that that that oops well what I was thinking was I I oops well what I was thinking was I I oops well what I was thinking was I I learned about multistage builds but I learned about multistage builds but I learned about multistage builds but I forgot that I'm actually already doing forgot that I'm actually already doing forgot that I'm actually already doing that so I'm running this this stage as that so I'm running this this stage as that so I'm running this this stage as the the the Builder and then it um compiles the go Builder and then it um compiles the go Builder and then it um compiles the go binary and then it copies that into

  49. binary and then it copies that into binary and then it copies that into my into the next stage yeah so the image my into the next stage yeah so the image my into the next stage yeah so the image is actually very lean is actually very lean is actually very lean already so if I do um already so if I do um already so if I do um Docker image Z oh yeah all right it's already 22 Z oh yeah all right it's already 22 megabytes I thought it was much larger I megabytes I thought it was much larger I megabytes I thought it was much larger I thought it was much larger but it must thought it was much larger but it must thought it was much larger but it must be an older project that I did I was be an older project that I did I was be an older project that I did I was confused about all right turns out my confused about all right turns out my confused about all right turns out my Docker file is already following best Docker file is already following best Docker file is already following best practices practices practices and in in many and in in many and in in many ways it is I just set this up really ways it is I just set this up really ways it is I just set this up really quick I haven't put much thought into it quick I haven't put much thought into it quick I haven't put much thought into it but now that I look at it it is but now that I look at it it is but now that I look at it it is it does use multi-stage builds to save it does use multi-stage builds to save it does use multi-stage builds to save some some some time but it's not running as a user time but it's not running as a user time but it's not running as a user though it is still running as root yeah yeah good point Edward I was just yeah yeah good point Edward I was just getting into that I'm I'm running it as getting into that I'm I'm running it as getting into that I'm I'm running it as root so that's that's an uh an upgrade root so that's that's an uh an upgrade root so that's that's an uh an upgrade we can do or an an improvement we can do

  50. we can do or an an improvement we can do we can do or an an improvement we can do here so just I just wanted to show you here so just I just wanted to show you here so just I just wanted to show you [Music] [Music] [Music] the gitops code for this application the gitops code for this application the gitops code for this application that I that I that I have here's the zcast and have here's the zcast and have here's the zcast and tracker and the customization tracker and the customization tracker and the customization file just reads in the file just reads in the file just reads in the base which reads in the deployment here so I haven't optimized deployment here so I haven't optimized the security for this yet so I can I can the security for this yet so I can I can the security for this yet so I can I can actually do that uh right actually do that uh right actually do that uh right now now now so I was running it as the root user so I was running it as the root user so I was running it as the root user here in the here in the here in the container so we can do container so we can do container so we can do run and run and run and then where was it the docker best then where was it the docker best then where was it the docker best practices alarn learn about that today let's put that on dark mode here today let's put that on dark mode here we user wait is not not here orry Docker user wait is not not here orry Docker file best practices practices user no way that user no way that user no way that must user really it's not listed as app user

  51. user really it's not listed as app user okay that's interesting user I'm just I the the course was user I'm just I the the course was talking about the docker best practices talking about the docker best practices talking about the docker best practices so I'm looking I'm interested in what so I'm looking I'm interested in what so I'm looking I'm interested in what they how they tell you to do it here run they how they tell you to do it here run they how they tell you to do it here run group group group at postgress all right if a service can run postgress all right if a service can run without privileges use user to change to without privileges use user to change to without privileges use user to change to non-root user yeah start by creating the user okay so yeah start by creating the user okay so they do explain it that's good I they do explain it that's good I they do explain it that's good I wouldn't have expected otherwise I was a wouldn't have expected otherwise I was a wouldn't have expected otherwise I was a little bit shocked but run group AD r little bit shocked but run group AD r little bit shocked but run group AD r postgress postgress postgress and user command well let's try try with this command well let's try try with this command post let's call it um post let's call it um app app app user so app

  52. so app user app that well let's see if this will that well let's see if this will work okay so Docker here oh yeah in Alpine it doesn't have here oh yeah in Alpine it doesn't have the group AD right it has a different um the group AD right it has a different um the group AD right it has a different um ad user Alpine here add group add user here this Alpine here add group add user here this is

  53. course now it should work course now it should work or build like this is fun I'm I'm usually I build like this is fun I'm I'm usually I I work always with setting up the I work always with setting up the I work always with setting up the Clusters and and and deploying the Clusters and and and deploying the Clusters and and and deploying the infrastructure and terraform but I infrastructure and terraform but I infrastructure and terraform but I actually don't do much U with Docker actually don't do much U with Docker actually don't do much U with Docker files and building applications on the files and building applications on the files and building applications on the daily so it's going to be it's much more daily so it's going to be it's much more daily so it's going to be it's much more fun to to see the other side of it a fun to to see the other side of it a fun to to see the other side of it a little bit and so it's nice little bit and so it's nice little bit and so it's nice to understand more of what I'm actually to understand more of what I'm actually to understand more of what I'm actually deploying on these clusters that's why this little project clusters that's why this little project is so nice because it's a silly little is so nice because it's a silly little is so nice because it's a silly little thing to see your zcast and stuff but thing to see your zcast and stuff but thing to see your zcast and stuff but yeah to optimize everything for security yeah to optimize everything for security yeah to optimize everything for security like now I'm making a small little step like now I'm making a small little step like now I'm making a small little step by running it as a nonroot user but I'm by running it as a nonroot user but I'm by running it as a nonroot user but I'm going to optimize the hell out of this I going to optimize the hell out of this I going to optimize the hell out of this I want to get into all of the go code and want to get into all of the go code and want to get into all of the go code and I I want to yeah make make this as I I want to yeah make make this as I I want to yeah make make this as secure as I can and I will learn a lot secure as I can and I will learn a lot secure as I can and I will learn a lot in the process but I have to like now I in the process but I have to like now I in the process but I have to like now I have the goal of the cks exam and I have have the goal of the cks exam and I have have the goal of the cks exam and I have to focus on that U but this one this to focus on that U but this one this to focus on that U but this one this actually is related to the C cks exam actually is related to the C cks exam actually is related to the C cks exam with the user and such but I I have to with the user and such but I I have to with the user and such but I I have to resist the urge to get too much too deep resist the urge to get too much too deep resist the urge to get too much too deep into the go code because that's what I into the go code because that's what I into the go code because that's what I really want to learn learn and I also really want to learn the cks

  54. and I also really want to learn the cks and I also really want to learn the cks I'm having a ton of fun studying for I'm having a ton of fun studying for I'm having a ton of fun studying for that I just have to make sure that I that I just have to make sure that I that I just have to make sure that I don't get distracted so it takes a while to build distracted so it takes a while to build this actually so I definitely have some um actually so I definitely have some um improvements to make in the security improvements to make in the security improvements to make in the security context as well I wonder I'm running it as well I wonder I'm running it as [Music] [Music] [Music] user add user I have to give a number user add user I have to give a number user add user I have to give a number here right in the security here right in the security here right in the security context context context let's let's let's see security context it always has to be on a user ID context it always has to be on a user ID so I have to give it so I have to give it so I have to give it a I have to give it a a user ID as well a I have to give it a a user ID as well a I have to give it a a user ID as well when building the docker file file okay the building is

  55. uh let's try to just run it on the uh let's try to just run it on the Rancher do I have Rancher desktop Rancher do I have Rancher desktop Rancher do I have Rancher desktop running yes I have one H the platform does not match so one H the platform does not match so that's because I'm running a kubernetes that's because I'm running a kubernetes that's because I'm running a kubernetes cluster on the I'm now on my n one Mech cluster on the I'm now on my n one Mech cluster on the I'm now on my n one Mech so this going to be interesting if it so this going to be interesting if it so this going to be interesting if it can actually run can actually run can actually run a um AMD 64 on an arm chip I I don't a um AMD 64 on an arm chip I I don't a um AMD 64 on an arm chip I I don't even know if this is going to work even know if this is going to work even know if this is going to work Locker working Locker working Locker XC XC XC it it it Dash are yeah we're running as app user now are yeah we're running as app user now that's that's that's good so it's working and interestingly I get

  56. working and interestingly I get permission tonight so permission tonight so permission tonight so unless unless unless I can root the that's interesting I can list the the that's interesting I can list the root file system but I root file system but I root file system but I can't uness the current working can't uness the current working can't uness the current working directory okay okay well is the is the thing okay okay well is the is the thing actually serving now and this going to actually serving now and this going to actually serving now and this going to be tricky because I have it already set be tricky because I have it already set be tricky because I have it already set up on my kubernetes up on my kubernetes up on my kubernetes cluster well anyway I made an cluster well anyway I made an cluster well anyway I made an improvement here on my Docker file and improvement here on my Docker file and improvement here on my Docker file and that's um as far as I wanted to go today that's um as far as I wanted to go today that's um as far as I wanted to go today the Pomo timer has reached 10 as well so the Pomo timer has reached 10 as well so the Pomo timer has reached 10 as well so I'm wrapping up the studies for today I'm wrapping up the studies for today I'm wrapping up the studies for today I'm very happy with the progress I've I'm very happy with the progress I've I'm very happy with the progress I've made and I've done some good practice made and I've done some good practice made and I've done some good practice with the RB back so thank you so much with the RB back so thank you so much with the RB back so thank you so much for tuning in guys that was uh nice to for tuning in guys that was uh nice to for tuning in guys that was uh nice to get some input there get some input there get some input there and um I'm going to be continuing the and um I'm going to be continuing the and um I'm going to be continuing the cks cks cks studies I've now finished the image studies I've now finished the image studies I've now finished the image footprint section and processes when footprint section and processes when footprint section and processes when that's done I have about 4 hours left that's done I have about 4 hours left that's done I have about 4 hours left and then I can really start preparing and then I can really start preparing and then I can really start preparing for the killer shell so I actually

  57. for the killer shell so I actually for the killer shell so I actually think maybe a think maybe a think maybe a week now maybe in two weeks I'm going to week now maybe in two weeks I'm going to week now maybe in two weeks I'm going to go for the ckss exam so I plan to do go for the ckss exam so I plan to do go for the ckss exam so I plan to do more cks streams in the more cks streams in the more cks streams in the meantime so thank you so much for tuning meantime so thank you so much for tuning meantime so thank you so much for tuning in and uh hope to see you in the next in and uh hope to see you in the next in and uh hope to see you in the next one have a good day

Summary

The main theme is making progress on a tech course focused on "killer Koda" scenarios, specifically related to container hardening and optimization. The speaker mentions working through scenarios involving API server misconfigurations and container footprints. The practical takeaway is the importance of consistently setting up environment configurations at the start of each scenario to streamline the learning process and avoid frustration.

View original episode ↗