← Back
Mischa Vandenburg April 15, 2024 1h 44m

πŸ“š K8s Studies - CKS - Finishing up all Killercoda

Read full transcript 64 segments
  1. okay we are live okay we are live again finishing up on the cks studies again finishing up on the cks studies again finishing up on the cks studies today I've been going through the course today I've been going through the course today I've been going through the course and I finished the video course finally and I finished the video course finally and I finished the video course finally the last 3 hours were a bit of a slog I the last 3 hours were a bit of a slog I the last 3 hours were a bit of a slog I was it's an 11-hour course and the last was it's an 11-hour course and the last was it's an 11-hour course and the last three hours were I was feeling it but I three hours were I was feeling it but I three hours were I was feeling it but I I went I'm I'm through it but to be I went I'm I'm through it but to be I went I'm I'm through it but to be honest I didn't do all of the killer honest I didn't do all of the killer honest I didn't do all of the killer Koda scenarios um in those last three Koda scenarios um in those last three Koda scenarios um in those last three hours so now I'm going to yeah finish hours so now I'm going to yeah finish hours so now I'm going to yeah finish them all up and get all these wonderful them all up and get all these wonderful them all up and get all these wonderful check marks here and it's going to be check marks here and it's going to be check marks here and it's going to be fun to see how much of the video fun to see how much of the video fun to see how much of the video watching actually stuck in to see if I watching actually stuck in to see if I watching actually stuck in to see if I can actually manage to fix these uh can actually manage to fix these uh can actually manage to fix these uh challenges as I'm going along hey there challenges as I'm going along hey there challenges as I'm going along hey there ansen welcome to the ansen welcome to the ansen welcome to the stream so without further Ado let's stream so without further Ado let's stream so without further Ado let's start the first one about app start the first one about app start the first one about app armor so if I understood it correctly armor so if I understood it correctly armor so if I understood it correctly app armor is like a way app armor is like a way app armor is like a way of um restricting the things that of um restricting the things that of um restricting the things that containers can do on your operating containers can do on your operating containers can do on your operating system ex check existing app armor profiles all ex check existing app armor profiles all right you asked to verify the following right you asked to verify the following right you asked to verify the following app armor profiles available on node one app armor profiles available on node one app armor profiles available on node one so I'm now on the control plane so I'll so I'm now on the control plane so I'll so I'm now on the control plane so I'll have have have to um first well always start with t-mo

  2. to um first well always start with t-mo to um first well always start with t-mo and set- OVI that's just the first thing and set- OVI that's just the first thing and set- OVI that's just the first thing I always do in these scenarios and let's I always do in these scenarios and let's I always do in these scenarios and let's check uh node one SSH node check uh node one SSH node check uh node one SSH node 01 and 01 and 01 and then these app armor then these app armor then these app armor profiles is it ATC app yeah app armor. D all right and then it's going to be D all right and then it's going to be local here so here we have the app armor local here so here we have the app armor local here so here we have the app armor profiles I think profiles I think profiles I think default snap no it's snap no it's not not not tunables force tunables force tunables force complain interesting is there another complain interesting is there another complain interesting is there another directory CD app directory CD app directory CD app armor maybe it's just app armor in armor in it no you've asked to verify if the no you've asked to verify if the following app are F profiles are following app are F profiles are following app are F profiles are available on node 01 oh it should only contain the profile oh it should only contain the profile names that are available on node one so names that are available on node one so names that are available on node one so let's check out the ones that are on let's check out the ones that are on let's check out the ones that are on control plane CD control plane CD control plane CD ATC app

  3. armor and let's armor and let's check oh wait they're already here these check oh wait they're already here these check oh wait they're already here these are the profiles are the profiles are the profiles probably user bin Firefox user bin man probably user bin Firefox user bin man probably user bin Firefox user bin man so let's open up Vim user bin so let's open up Vim user bin so let's open up Vim user bin Firefox yeah this is an uh an app armor profile yeah profile Firefox here we go profile yeah profile Firefox here we go okay so these are the profiles these are okay so these are the profiles these are okay so these are the profiles these are the ones on the control the ones on the control the ones on the control plane and let's go plane and let's go plane and let's go back CD back CD back CD at to see app at to see app at to see app armor. D okay so these are all the ones that D okay so these are all the ones that are available on node are available on node are available on node 01 you're asked to verify if the 01 you're asked to verify if the 01 you're asked to verify if the following app armor profiles are following app armor profiles are following app armor profiles are available on node01 well deer Docker available on node01 well deer Docker available on node01 well deer Docker default is not default is not default is not here snap is not here either ftpd is also not here well maybe either ftpd is also not here well maybe I should should I should should I should should um find then let's see grab then let's see grab Docker nothing there and is there Docker nothing there and is there Docker nothing there and is there anything on the control plane find dot anything on the control plane find dot anything on the control plane find dot grab Docker

  4. Docker no so no so no so is the answer that none of them are is the answer that none of them are is the answer that none of them are available here TCP here TCP dump is that one here yeah TCP dump is available here here yeah TCP dump is available here nothing about nothing about nothing about FTP so I think it's all of these FTP so I think it's all of these FTP so I think it's all of these actually it should only contain these profiles it should only contain these profiles names that are available on node one names that are available on node one names that are available on node one well then it's user bin TCP well then it's user bin TCP well then it's user bin TCP dump and then go dump and then go dump and then go to Vim root profiles. dxt I think it's only that one dxt I think it's only that one actually let's actually let's actually let's check and I'm wrong so the how would one find the rest of these the how would one find the rest of these profiles ftpd find dot grab ftpd find dot grab ftpd nothing nothing crab crab crab fcpd can we find something then

  5. local oh wait there's probably more on local oh wait there's probably more on in local too so let's go into local then in local too so let's go into local then in local too so let's go into local then in the control in the control in the control plane in local there's also more so is there there is some thing about snap there there is some thing about snap here is that on node here is that on node here is that on node [Music] [Music] [Music] 01 snapd is here as 01 snapd is here as 01 snapd is here as well okay so snapd we also need well okay so snapd we also need well okay so snapd we also need to add I to add I to add I suppose copy copy [Music] boom snap boom snap that one was there that one was there that one was there [Music] [Music] [Music] too check still not okay I'm just going too check still not okay I'm just going too check still not okay I'm just going to look at the solution to look at the solution to look at the solution because oh app armor status of because oh app armor status of because oh app armor status of course course course yeah yeah yeah armor I was going armor I was going armor I was going the file route whereas I should have the file route whereas I should have the file route whereas I should have just ran the command and then it would just ran the command and then it would just ran the command and then it would have been very easy to just have been very easy to just have been very easy to just app armor status and then pipe that to app armor status and then pipe that to app armor status and then pipe that to less and now I could have searched for less and now I could have searched for less and now I could have searched for Docker and here I would see Docker Docker and here I would see Docker Docker and here I would see Docker default yeah all right I was just an default yeah all right I was just an default yeah all right I was just an idiot okay well that's how you learn

  6. idiot okay well that's how you learn idiot okay well that's how you learn right you make mistakes so Docker is right you make mistakes so Docker is right you make mistakes so Docker is here well I was not far here well I was not far here well I was not far actually so only the only one that I was actually so only the only one that I was actually so only the only one that I was missing was Docker so where is Docker missing was Docker so where is Docker missing was Docker so where is Docker then FD then FD then FD find DOT type find DOT type find DOT type f name f name f name Docker nothing about Docker nothing about Docker nothing about Docker it is one of these ones that are Docker it is one of these ones that are Docker it is one of these ones that are [Music] [Music] [Music] installed by installed by installed by default LS tunables well anyway Docker was the only tunables well anyway Docker was the only one that I was missing one that I was missing one that I was missing missing I think so if I open this one missing I think so if I open this one missing I think so if I open this one again and I add again and I add again and I add Docker and check then it's successful Docker and check then it's successful Docker and check then it's successful okay next there is an existing okay next there is an existing okay next there is an existing deployment named space cow in nam space deployment named space cow in nam space deployment named space cow in nam space Moon it should be configured to use app Moon it should be configured to use app Moon it should be configured to use app armor profile Docker default but armor profile Docker default but armor profile Docker default but something seems wrong fix it okay so we something seems wrong fix it okay so we something seems wrong fix it okay so we are going to check out okay n moon and edit out okay n moon and edit deploy space deploy space deploy space go and then there is it should be configured to use app is it should be configured to use app Aral Docker default but something seems

  7. Aral Docker default but something seems Aral Docker default but something seems wrong wrong wrong well I don't see any label with app well I don't see any label with app well I don't see any label with app armor because that's how you do it armor because that's how you do it armor because that's how you do it [Music] [Music] [Music] you you you basically add an uh you you you basically add an uh you you you basically add an uh annotation to it armor restrict the containers access to armor restrict the containers access to Resource with app armor okay here here you okay here here you go they are specified per container and go they are specified per container and go they are specified per container and to specify the profile add an annotation to specify the profile add an annotation to specify the profile add an annotation to the P's metadata but that's strange it should be but that's strange it should be configured to use app armor profile but configured to use app armor profile but configured to use app armor profile but something seems wrong that that implies something seems wrong that that implies something seems wrong that that implies that it has this annotation but that it that it has this annotation but that it that it has this annotation but that it is that they misconfigured it or that is that they misconfigured it or that is that they misconfigured it or that the profile is missing oh here we go here is the thing missing oh here we go here is the thing ah Why didn't it come up earlier oh well ah Why didn't it come up earlier oh well ah Why didn't it come up earlier oh well container app container app container app Armor security beta let's check out if Armor security beta let's check out if Armor security beta let's check out if that that that matches container app Armor security matches container app Armor security matches container app Armor security beta kubernetes beta kubernetes beta kubernetes IO slash container okay so it's not IO slash container okay so it's not IO slash container okay so it's not referring to the right container referring to the right container referring to the right container name so

  8. name so name so the there's only one container in this the there's only one container in this the there's only one container in this deployment it only has the one in the deployment it only has the one in the deployment it only has the one in the list so the name is list so the name is list so the name is httpd httpd httpd so this needs to be changed so this needs to be changed so this needs to be changed to to to httpd this one can be deleted and if I httpd this one can be deleted and if I httpd this one can be deleted and if I now delete it then K and moon get pods it's actually not redeploying pods it's actually not redeploying that's that's that's interesting but maybe it doesn't need to interesting but maybe it doesn't need to interesting but maybe it doesn't need to be oh I should be oh I should be oh I should probably enable screen keys here here we probably enable screen keys here here we probably enable screen keys here here we go okay so hello Nikos welcome to the stream so hello Nikos welcome to the stream Nikos I hope I pronounced that Nikos I hope I pronounced that Nikos I hope I pronounced that correctly so I've edited the edited the correctly so I've edited the edited the correctly so I've edited the edited the deployment and let's just verify deployment and let's just verify deployment and let's just verify that the annotation is correct that the annotation is correct that the annotation is correct yeah so let's check it no it yeah so let's check it no it yeah so let's check it no it failed so I edited failed so I edited failed so I edited the the the Local Host Docker default let's see

  9. the Local Host Docker default let's see if the deployment actually is available if the deployment actually is available if the deployment actually is available so first let's check where the pods are so first let's check where the pods are so first let's check where the pods are actually running okay get actually running okay get actually running okay get pods n Moon o wide so they're all on pods n Moon o wide so they're all on pods n Moon o wide so they're all on node 01 so that's where I will need to node 01 so that's where I will need to node 01 so that's where I will need to be be be looking and on my node looking and on my node looking and on my node one I couldn't find the docker one I couldn't find the docker one I couldn't find the docker default so it needs to have the docker default so it needs to have the docker default so it needs to have the docker default there default there default there so let's see if we can find this file on so let's see if we can find this file on so let's see if we can find this file on the control plane at C app and and then find then find then find dot name Docker there's nothing about dot name Docker there's nothing about dot name Docker there's nothing about Docker here here um where is the the docker default um where is the the docker default um where is the the docker default profile usually located on a profile usually located on a profile usually located on a system CD at to C app armor wait maybe I armor wait maybe I can what was it app armor status

  10. status grab Docker no pipe it to less and then grab Docker no pipe it to less and then grab Docker no pipe it to less and then search for search for search for Docker here docker default so it is Docker here docker default so it is Docker here docker default so it is here now is there like a app status status um um um no it would be nice if I could figure no it would be nice if I could figure no it would be nice if I could figure out out out from the from the CLI where the profile from the from the CLI where the profile from the from the CLI where the profile is located because at because at C at C app armor I'm I seem to be unable C at C app armor I'm I seem to be unable C at C app armor I'm I seem to be unable to locate the docker default file for to locate the docker default file for to locate the docker default file for some reason there nothing here and then in reason there nothing here and then in ETC app armor ETC app armor ETC app armor [Music] [Music] [Music] D grab D grab D grab doc there's also nothing about Docker so doc there's also nothing about Docker so doc there's also nothing about Docker so why is that profile not available here why is that profile not available here why is that profile not available here well at least the file name is not well at least the file name is not well at least the file name is not here it's not the file is not named here it's not the file is not named here it's not the file is not named Docker so if I just find if I just tree

  11. Docker so if I just find if I just tree Docker so if I just find if I just tree this or just find Dot and pipe that to less Dot and pipe that to less what do we see we see disabled tunables then we have tunables then we have Nvidia these are all abstractions is there anything about abstractions is there anything about Docker here no default no this is Docker here no default no this is Docker here no default no this is all if I search this for Docker it's not all if I search this for Docker it's not all if I search this for Docker it's not here not in the control here not in the control here not in the control plan and in CD ATC up armor D find dot pipe that to D find dot pipe that to less there's nothing about Docker here less there's nothing about Docker here less there's nothing about Docker here either so that's really strange where is either so that's really strange where is either so that's really strange where is that file then well I got to look at the solution then well I got to look at the solution the app arm profile will be configured the app arm profile will be configured the app arm profile will be configured via annotation via annotation via annotation yep that's correct yeah well that's what I've done correct yeah well that's what I've done right I've done this this [Music] [Music] [Music] um well

  12. wait okay edit wait okay edit deploy and Moon space deploy and Moon space deploy and Moon space c oh c oh c oh okay I've added it to the deployment okay I've added it to the deployment okay I've added it to the deployment level so level so level so I have to take this line and then add it I have to take this line and then add it I have to take this line and then add it to the spec or the template to the spec or the template to the spec or the template level level level so just get this whole block of so just get this whole block of so just get this whole block of annotations under metadata okay and then this remove this one so okay and then this remove this one so now that's also why the deployment was now that's also why the deployment was now that's also why the deployment was not redeploying and if I now get the pods in redeploying and if I now get the pods in namespace namespace namespace Moon yeah now they've all Moon yeah now they've all Moon yeah now they've all redeployed and if I check now yeah this redeployed and if I check now yeah this redeployed and if I check now yeah this these are these dangerous little rabbit these are these dangerous little rabbit these are these dangerous little rabbit holes that you you can get into like now holes that you you can get into like now holes that you you can get into like now I was poking around the file I was poking around the file I was poking around the file system um system um system um and sure I've now learned that I can't and sure I've now learned that I can't and sure I've now learned that I can't actually see the docker actually see the docker actually see the docker default file so it has been useful but default file so it has been useful but default file so it has been useful but these are not the kind of things that these are not the kind of things that these are not the kind of things that you want to be doing on these time timed you want to be doing on these time timed you want to be doing on these time timed exams right that's going to be real exams right that's going to be real exams right that's going to be real Dangerous Time Dangerous Time Dangerous Time syncs there's an app armor profile at syncs there's an app armor profile at syncs there's an app armor profile at root profile it should be referenced by root profile it should be referenced by root profile it should be referenced by the name Dr engine custom

  13. the name Dr engine custom the name Dr engine custom installed on nodes control play and no installed on nodes control play and no installed on nodes control play and no 01 01 01 sure you got it I can do this I can do sure you got it I can do this I can do sure you got it I can do this I can do this I'm failing but I'm learning this I'm failing but I'm learning this I'm failing but I'm learning shouldn't be afraid to fail uh there's an app armor profile at fail uh there's an app armor profile at root profile CD root profile CD root profile CD root yeah cat profile all right this is root yeah cat profile all right this is root yeah cat profile all right this is a big file a big file a big file Vim X it should be referenced by name Docker X it should be referenced by name Docker engine X engine X engine X custom custom custom well that's easy it should just be well that's easy it should just be well that's easy it should just be called that called that called that then and then engine then and then engine then and then engine X Docker engine X check if there are X Docker engine X check if there are X Docker engine X check if there are more references doer engine more references doer engine more references doer engine X nope no more X nope no more X nope no more references so that should be it then and it should be referenced by name then and it should be referenced by name Docker engine X custom installed on noes Docker engine X custom installed on noes Docker engine X custom installed on noes control plane and node control plane and node control plane and node 01 01 01 so I will copy the file so I will copy the file so I will copy the file profile to s profile to s profile to s see app

  14. see app see app armor. custom custom and then there is this command app and then there is this command app and then there is this command app armor parer so now it should parse that so now it should parse that directory and then I should see the directory and then I should see the directory and then I should see the profile in app armor status it's taking a long status it's taking a long time so that is worrying me okay something is okay something is wrong um app armor status do we see anything um app armor status do we see anything here

  15. 37 profiles are loaded is there anything 37 profiles are loaded is there anything about engine x no so it's probably running into a problem here app probably running into a problem here app armor armor armor parer so what can I've have done wrong um CD ATC app um CD ATC app armor armor armor D maybe I should move it to local yeah let's try that move Docker local yeah let's try that move Docker engine X custom to local why is it lighting up differently why is it lighting up differently LSL oh it has different permissions read write permissions read write X read XR so it shouldn't it should be X read XR so it shouldn't it should be X read XR so it shouldn't it should be readable cat Docker engine X custom yeah readable cat Docker engine X custom yeah readable cat Docker engine X custom yeah so now I if I do app armor working do I working do I [Music]

  16. see anything in the CIS logs about see anything in the CIS logs about this journal CTL armor armor no okay well this scenario has not gone no okay well this scenario has not gone no okay well this scenario has not gone well for me I've had to look at all of well for me I've had to look at all of well for me I've had to look at all of the solutions all the time but hey the solutions all the time but hey the solutions all the time but hey that's how you learn that's how you learn that's how you learn I give up now tip the following line I give up now tip the following line I give up now tip the following line sets to this profile's name Docker sets to this profile's name Docker sets to this profile's name Docker engine engine engine X yeah well that's what X yeah well that's what X yeah well that's what I've changed so Vim Docker engine X I've changed so Vim Docker engine X I've changed so Vim Docker engine X custom here's the different file name custom here's the different file name custom here's the different file name that I directory really is that what I was directory really is that what I was doing wrong app armor parer and then et doing wrong app armor parer and then et doing wrong app armor parer and then et C app C app C app armor.

  17. D okay so now it D okay so now it edited if I now do app armor edited if I now do app armor edited if I now do app armor status and then grab for engine status and then grab for engine status and then grab for engine X it's not added folder yep now it's in the engine X so folder yep now it's in the engine X so if I grab it now um now um Docker engine X custom and that's now Docker engine X custom and that's now Docker engine X custom and that's now active all right so now it works so now active all right so now it works so now active all right so now it works so now I just need to copy that over to no one I just need to copy that over to no one I just need to copy that over to no one so then so then so then SCP uh Docker engine X SCP uh Docker engine X SCP uh Docker engine X custom to node one custom to node one custom to node one slash um at c f armor. d local could not resolve no node name no local could not resolve no node name no node 01 node 01 node 01 of course of course of course node 01 set- node 01 set- node 01 set- OVI and if I now go over to node OVI and if I now go over to node OVI and if I now go over to node one in the local directory we now have one in the local directory we now have one in the local directory we now have our Docker engine X custom and if I then our Docker engine X custom and if I then our Docker engine X custom and if I then app app app armor parser if I do dot do will that work yep

  18. parser if I do dot do will that work yep now it now it now it worked and if I then app armor status and grab that for Docker here we status and grab that for Docker here we go here's Docker engine X go here's Docker engine X go here's Docker engine X custom custom custom so what did I learn I learned quite a so what did I learn I learned quite a so what did I learn I learned quite a lot uh from doing this one um let's lot uh from doing this one um let's lot uh from doing this one um let's see if I open up my cks see if I open up my cks see if I open up my cks course notes and I'm going to course notes and I'm going to course notes and I'm going to be adding that to where shall I call it be adding that to where shall I call it be adding that to where shall I call it containers Mission controller well I'll containers Mission controller well I'll containers Mission controller well I'll just make another entry armor used to restrict armor used to restrict processes um must processes um must processes um must know app armor status app armor armor status app armor parser parser parser important must give path to app important must give path to app important must give path to app armor

  19. parer also make make sure to parer also make make sure to add the label to the Pod spec and not add the label to the Pod spec and not add the label to the Pod spec and not deployment deployment deployment spec so now they should be so now they should be solved yeah validation successful all solved yeah validation successful all solved yeah validation successful all right back to the right back to the right back to the scenarios I realize I didn't start a scenarios I realize I didn't start a scenarios I realize I didn't start a uh Pomodoro Timer I can see I've been live for 28 Timer I can see I've been live for 28 minutes so I I'll do one more scenario minutes so I I'll do one more scenario minutes so I I'll do one more scenario and then I'm going to have a little and then I'm going to have a little and then I'm going to have a little break man third 38 that was 20 like that break man third 38 that was 20 like that break man third 38 that was 20 like that was almost half an hour on one scenario was almost half an hour on one scenario was almost half an hour on one scenario and of course I'm still learning but you and of course I'm still learning but you and of course I'm still learning but you don't want to be in this kind of don't want to be in this kind of don't want to be in this kind of situation in the exam you know then situation in the exam you know then situation in the exam you know then you're going to be in big trouble so you're going to be in big trouble so you're going to be in big trouble so definitely a scenario to repeat actually definitely a scenario to repeat actually definitely a scenario to repeat actually I have a note on that I have a note on that I have a note on that scenarios to scenarios to scenarios to repeat at CD encryption that was fun but repeat at CD encryption that was fun but repeat at CD encryption that was fun but let's add app armor let's add app armor let's add app armor here that's definitely didn't go smooth here that's definitely didn't go smooth here that's definitely didn't go smooth so going to do that so going to do that so going to do that more let's do auditing enable audit logging I remember that was quite logging I remember that was quite straightforward forward but let's see

  20. straightforward forward but let's see straightforward forward but let's see set Dash uh start with t-o and then set- set Dash uh start with t-o and then set- set Dash uh start with t-o and then set- OVI first thing I OVI first thing I OVI first thing I do configure the API server for audit do configure the API server for audit do configure the API server for audit logging the log path should be at C logging the log path should be at C logging the log path should be at C kubernetes audit logs audit kubernetes audit logs audit kubernetes audit logs audit log on the host and inside the container log on the host and inside the container log on the host and inside the container the existing audit policy to use is at the existing audit policy to use is at the existing audit policy to use is at here but should be the same on the host here but should be the same on the host here but should be the same on the host and inside the and inside the and inside the container okay so audit so audit log I think it's in the cube API server server auditing auditing auditing auditing audit auditing audit auditing audit policy so these are the policies that policy so these are the policies that policy so these are the policies that are are are there okay that's an that's where how we need okay that's an that's where how we need to configure the volumes and now let's check the cube the volumes and now let's check the cube API server for the right flag [Music] [Music] audit these are all audit these are all audit these are all just configuration strings but is there just configuration strings but is there just configuration strings but is there also it webo config

  21. it webo config [Music] parameters like how to configure it but parameters like how to configure it but isn't there like what isn't there like what isn't there like what audits audit logging enabled or where audits audit logging enabled or where audits audit logging enabled or where the config file is I only see a web H the config file is I only see a web H the config file is I only see a web H hope config file okay so let's see what the audit file okay so let's see what the audit the API server manifest looks like now the API server manifest looks like now the API server manifest looks like now CD at C manifests let's see let's see kubernetes kubernetes kubernetes manifests and check out the manifests and check out the manifests and check out the cube API cube API cube API server nothing about audit logging here server nothing about audit logging here server nothing about audit logging here the log path should be at C kubernetes the log path should be at C kubernetes the log path should be at C kubernetes audit audit audit logs so is there anything about log path logs so is there anything about log path logs so is there anything about log path here log batch locom press locom press format Max size

  22. mode here's the audit policy mode here's the audit policy configuration oh here audit policy file configuration oh here audit policy file configuration oh here audit policy file I think that's the one we I think that's the one we I think that's the one we need the yeah the yeah probably in the policy is defined where probably in the policy is defined where probably in the policy is defined where the log should the log should the log should be so create a new window and then let's be so create a new window and then let's be so create a new window and then let's check out the policy file Vim at check out the policy file Vim at check out the policy file Vim at [Music] C policy C policy yl no this is just the the yaml there I have the this parameter audit there I have the this parameter audit audit policy audit policy audit policy file well let's just start with that one nothing else here so I'm going to one nothing else here so I'm going to add the add the add the flag audit policy file that one is this one file that one is this one the ATC kubernetes audit policy that's that's for sure and is policy that's that's for sure and is there anything about log in here there anything about log in here there anything about log in here [Music]

  23. no ah audit log path here we go audit no ah audit log path here we go audit log path that's it so audit log then we need to then we need to add add add the yeah oh this is a nice type file okay yeah oh this is a nice type file okay okay that's a nice example nice of them okay that's a nice example nice of them okay that's a nice example nice of them to add that here so we have a volume here and we'll call here and we'll call that audit policy the path policy the path is policy. yo here oops okay and then we have to make a oops okay and then we have to make a volume Mount of audit policy up volume Mount of audit policy up volume Mount of audit policy up here Mount path path name audit name audit name audit policy and that needs to be on the same

  24. there we there we go go go um audit policy audit um audit policy audit um audit policy audit policy and here we go that was the policy and here we go that was the policy and here we go that was the policy file and policy file and policy file and then the audit log is just a directory it as a particular file so that's it as a particular file so that's interesting the log path should be at C interesting the log path should be at C interesting the log path should be at C kubernetes logs audit. log and what do what do I say here audit log and what do what do I say here audit log path well I wonder if I I I'm going to path well I wonder if I I I'm going to try as a try as a try as a file but but maybe it will just create file but but maybe it will just create file but but maybe it will just create the the file named audit. log at that the the file named audit. log at that the the file named audit. log at that location and I have location and I have location and I have to U mount it as a directory but let's to U mount it as a directory but let's to U mount it as a directory but let's just try it like this also going to mount the this as a this also going to mount the this as a file and then have a volume mount

  25. log and here they're log and here they're saying read only okay yeah so it's telling it okay yeah so it's telling it to okay yeah here it's already to okay yeah here it's already to okay yeah here it's already configured like this so I just follow configured like this so I just follow configured like this so I just follow exactly what is exactly what is exactly what is here so here I don't change anything but here so here I don't change anything but here so here I don't change anything but the type is directory or create just the type is directory or create just the type is directory or create just like it is in the documentation like it is in the documentation like it is in the documentation so go going back back down to here here okay so audit policy and audit okay so audit policy and audit okay so audit policy and audit log audit policy and audit log audit policy and audit log audit policy and audit log this should be log this should be log this should be it okay get PS API server is down so that means that PS API server is down so that means that it's being it's being it's being restarted so I'm going to watch N1 restarted so I'm going to watch N1 restarted so I'm going to watch N1 cctl PS the API server is currently not up

  26. PS the API server is currently not up so I must have broken so I must have broken so I must have broken something and then let's check out VAR something and then let's check out VAR something and then let's check out VAR log log log pod and pod and pod and then check out the then check out the then check out the Cube Cube Cube system API server let's see error unknown flag server let's see error unknown flag audit log audit log audit log path okay um let's um let's see kubernetes manifests ah I'm forgetting manifests ah I'm forgetting the equal that changes that changes anything I might have to move the file anything I might have to move the file anything I might have to move the file back and back and back and forth I'm just going to give it a little forth I'm just going to give it a little forth I'm just going to give it a little bit of time maybe it will detect a bit of time maybe it will detect a bit of time maybe it will detect a change yeah here we go and it instantly

  27. change yeah here we go and it instantly change yeah here we go and it instantly closed insta closed insta closed insta close insta close insta close insta close [Music] [Music] directory ah okay Vim Cube API server yep here this okay Vim Cube API server yep here this flag is wrong it should just be audit flag is wrong it should just be audit flag is wrong it should just be audit logs probably let's check the logs probably let's check the logs probably let's check the documentation no oh wait yeah this should be audit.

  28. no oh wait yeah this should be audit. log but the slash audit and then this should also be slash audit and then this should also be just SL audit here we audit here we go now it should file so move Cube API file so move Cube API [Music] [Music] [Music] server to the previous directory and server to the previous directory and server to the previous directory and then I move it back again restart oh come on

  29. restart oh come on man are you just teasing me let's see if there are some new logs let's see if there are some new logs then CD Cube system Cube API server oh number four so we are we are server oh number four so we are we are definitely moving up open at C kubernetes audit logs up open at C kubernetes audit logs audit. log is a directory what do you mean it's a directory what do you mean it's a directory mcube API server.

  30. mcube API server. yo I've done it exactly yo I've done it exactly yo I've done it exactly like here audit log path audit log path audit log path that needs to be like this VAR log path that needs to be like this VAR log path that needs to be like this VAR log kubernetes audit audit. log oh wait aha the log path should be at C oh wait aha the log path should be at C kubernetes maybe I was messing up those was messing up those paths ATC kubernetes audit logs audit. log Mount path ety kubernetes audit log Mount path ety kubernetes audit logs Mount logs Mount logs Mount path Etsy path Etsy path Etsy kubernetes SL audits but I have it as audit logs and audits but I have it as audit logs and then down then down then down here I also have it as Etsy kubernetes here I also have it as Etsy kubernetes here I also have it as Etsy kubernetes audit they're both host path Etsy kubernetes

  31. they're both host path Etsy kubernetes audit path so that's correct then the mount path so that's correct then the mount path is at C kubernetes audit path is at C kubernetes audit path is at C kubernetes audit logs read only false so it should be logs read only false so it should be logs read only false so it should be able to able to able to write and then write and then write and then here the audit log path is at C here the audit log path is at C here the audit log path is at C kubernetes audit kubernetes audit kubernetes audit logs / audit.

  32. because et's see because et's see kubernetes CD audit logs uh wait there is I think logs uh wait there is I think because what I did wrong just now it it because what I did wrong just now it it because what I did wrong just now it it created a directory at that location on created a directory at that location on created a directory at that location on the Node so if there's nothing in this if there's nothing in this directory this is just a directory so if directory this is just a directory so if directory this is just a directory so if I if I remove this I if I remove this I if I remove this directory okay now the directory is gone directory okay now the directory is gone directory okay now the directory is gone and now when the Pod restarts something different must something different must happen this must be it this must be it it so here we go Cube API server is running so here we go Cube API server is running so here we go Cube API server is running 6 6 6 seconds oh that was a that was a weird seconds oh that was a that was a weird seconds oh that was a that was a weird one and like this these are these moments and like this these are these moments where I'm really happy that I have a where I'm really happy that I have a where I'm really happy that I have a solid understanding of solid understanding of solid understanding of Linux Linux Linux because like what are you going to do because like what are you going to do because like what are you going to do like I knew I I needed to check out that

  33. like I knew I I needed to check out that like I knew I I needed to check out that path on the path on the path on the system and check out if something was system and check out if something was system and check out if something was wrong there because I had this strange wrong there because I had this strange wrong there because I had this strange error message error message error message saying this is a directory saying this is a directory saying this is a directory like oh I'm so glad that this that I like oh I'm so glad that this that I like oh I'm so glad that this that I knew that I figured it out so if I check knew that I figured it out so if I check knew that I figured it out so if I check now the validation failed but at least now the validation failed but at least now the validation failed but at least the API server is coming up so I'm the API server is coming up so I'm the API server is coming up so I'm almost there so what I am missing now is these there so what I am missing now is these two flags where I am setting the max two flags where I am setting the max two flags where I am setting the max size so we're going to add those and finally we're going to add those and finally we're going to add this one Max this one Max this one Max backup here we backup here we backup here we go now the API server should restart in go now the API server should restart in go now the API server should restart in a few Flags it's not restarting yet but maybe Flags it's not restarting yet but maybe it's just finishing it's just finishing it's just finishing some some requests or something or I some some requests or something or I some some requests or something or I might have to change the might have to change the might have to change the file or move the file I mean now here he file or move the file I mean now here he file or move the file I mean now here he goes here goes the cube API server it's back up it's staying server it's back up it's staying up okay get

  34. up okay get up okay get pods it's up check pods it's up check pods it's up check successful yes I did it I'm not a successful yes I did it I'm not a successful yes I did it I'm not a complete complete complete donkey but it was again a bit of too donkey but it was again a bit of too donkey but it was again a bit of too much stumbling around oh well well there was two around oh well well there was two scenarios so I've done the app armor scenarios so I've done the app armor scenarios so I've done the app armor that's checked off the audit log what's that's checked off the audit log what's that's checked off the audit log what's what is the next what is the next what is the next one these ones I've done these ones I've one these ones I've done these ones I've one these ones I've done these ones I've done F CCO chain rule all right so I'm done F CCO chain rule all right so I'm done F CCO chain rule all right so I'm going to take a short break I'll be back going to take a short break I'll be back going to take a short break I'll be back in five or 10 minutes minutes and in five or 10 minutes minutes and in five or 10 minutes minutes and probably 5 minutes or so and then I will probably 5 minutes or so and then I will probably 5 minutes or so and then I will uh do the Falco scenario and that is and that is actually one of the few and then there actually one of the few and then there actually one of the few and then there are a few more scenarios that I still are a few more scenarios that I still are a few more scenarios that I still need to do but I'm getting close all need to do but I'm getting close all need to do but I'm getting close all right short break and then I'll be back right short break and then I'll be back right short break and then I'll be back soon five or 10 soon five or 10 soon five or 10 minutes start break so we're back again and I'm holding my

  35. so we're back again and I'm holding my hand up to the camera because then it hand up to the camera because then it hand up to the camera because then it starts tracking my face this like the starts tracking my face this like the starts tracking my face this like the signal for it to start tracking signal for it to start tracking signal for it to start tracking it so are you ready for another round of so are you ready for another round of killer killer killer Koda let's do it let's get into Falco and actually now I let's get into Falco and actually now I am going to start a Pomo so Falco change Rule and again like I said I've been Rule and again like I said I've been I've watched the last four hours of the I've watched the last four hours of the I've watched the last four hours of the course without doing any of the course without doing any of the course without doing any of the scenarios and now I'm just testing how scenarios and now I'm just testing how scenarios and now I'm just testing how much of that information I've actually much of that information I've actually much of that information I've actually retained just as an experiment retained just as an experiment retained just as an experiment TMX set- TMX set- TMX set- oovi start Falco has been installed on oovi start Falco has been installed on oovi start Falco has been installed on node control plane and it runs as a node control plane and it runs as a node control plane and it runs as a service it's configured to log to CIS service it's configured to log to CIS service it's configured to log to CIS log and this is where the verification log and this is where the verification log and this is where the verification for this scenario also looks cause the for this scenario also looks cause the for this scenario also looks cause the rule shell in a container to log by rule shell in a container to log by rule shell in a container to log by creating a new creating a new creating a new pod executing pod executing pod executing it and then check the fgo logs container it and then check the fgo logs container it and then check the fgo logs container related out so k

  36. so k run engine X image is engine X Alpine Alpine kxc engine X shell I shell but it's I I didn't EXA in shell I shell but it's I I didn't EXA in um I in interactive mode but then let's um I in interactive mode but then let's um I in interactive mode but then let's see configure to log to CIS log so see configure to log to CIS log so see configure to log to CIS log so opening a new um pane window I'm going opening a new um pane window I'm going opening a new um pane window I'm going to go into Journal to go into Journal to go into Journal CTL check CTL check CTL check here and here error package manage here and here error package manage here and here error package manage process launch in container user rout process launch in container user rout process launch in container user rout engine X container so here is something FCO interestingly it said package FCO interestingly it said package management process launched in management process launched in management process launched in container but it is the container name engine name engine X container X container X container ID yeah it should be that one ID yeah it should be that one ID yeah it should be that one like that was not so long ago so here we like that was not so long ago so here we like that was not so long ago so here we saw the log entry so let's check saw the log entry so let's check saw the log entry so let's check it oh it

  37. again like I'm now in the Shell so do I again like I'm now in the Shell so do I see any output of that see any output of that see any output of that here Journal CTL here notice a shell was spawned in a here notice a shell was spawned in a container with attached terminal ah okay container with attached terminal ah okay container with attached terminal ah okay maybe that was the problem I didn't do maybe that was the problem I didn't do maybe that was the problem I didn't do it in um interactive mode so now it it in um interactive mode so now it it in um interactive mode so now it validated okay change the FCO output of validated okay change the FCO output of validated okay change the FCO output of rule terminal shell in container rule terminal shell in container rule terminal shell in container to include New Shell the very beginning to include New Shell the very beginning to include New Shell the very beginning yada yada yada yada sure so then we have to modify the yada sure so then we have to modify the yada sure so then we have to modify the falcore rule so let's go to at C see falcore rule so let's go to at C see falcore rule so let's go to at C see Falco I think Falco I think Falco I think Falco I love Linux you just all of the Falco I love Linux you just all of the Falco I love Linux you just all of the configuration is in at C it's just so configuration is in at C it's just so configuration is in at C it's just so predictable and you always know exactly predictable and you always know exactly predictable and you always know exactly where to go it's just I love it there is where to go it's just I love it there is where to go it's just I love it there is a rules. d so that means a directory a rules. d so that means a directory a rules. d so that means a directory containing all of the rules uh it's probably the Falco rules rules uh it's probably the Falco rules local so Vim local so Vim local so Vim Falco rules low yo it's not that one then it's just yo it's not that one then it's just Falco rules.

  38. Falco rules. Falco rules. yo and then we had something about yo and then we had something about yo and then we had something about Shell Shell it it [Music] f here a f here a shell was spawned so let's search for shell was spawned so let's search for shell was spawned so let's search for spawned in the file spawned well a shell was well a shell was spawned here output a shell was spawned spawned here output a shell was spawned spawned here output a shell was spawned in a container with an attached terminal in a container with an attached terminal in a container with an attached terminal here we go output go output yeah so include New Shell at the very yeah so include New Shell at the very yeah so include New Shell at the very beginning new beginning new beginning new [Music] then and then include repo container

  39. then and then include repo container image repository at any position sure so that's now sure so that's now added added added it cause CIS Lo output Again by creating it cause CIS Lo output Again by creating it cause CIS Lo output Again by creating a shell in that pod so pod so I'm out of the pot again and then I'm I'm out of the pot again and then I'm I'm out of the pot again and then I'm going going going to run that command again to trigger the to run that command again to trigger the to run that command again to trigger the rule Journal CTL and then here we see the new you can CTL and then here we see the new you can see it down here my head is not covering see it down here my head is not covering see it down here my head is not covering it New Shell a shell was spawned and it New Shell a shell was spawned and it New Shell a shell was spawned and then I'm trusting that here the user ID is zero and repo that here the user ID is zero and repo Docker iio is Library I'm covering it Docker iio is Library I'm covering it Docker iio is Library I'm covering it but you can you trust me it's there so but you can you trust me it's there so but you can you trust me it's there so it should now it should it should now it should it should now it should um yeah it should validate correctly um yeah it should validate correctly um yeah it should validate correctly challenge solved well that was easy challenge solved well that was easy challenge solved well that was easy there was a lot less stumbling around there was a lot less stumbling around there was a lot less stumbling around than the previous ones Dear God than the previous ones Dear God than the previous ones Dear God okay back to the okay back to the okay back to the scenarios and I'm I'm just I just love scenarios and I'm I'm just I just love scenarios and I'm I'm just I just love it to that it chose the check mark here it to that it chose the check mark here it to that it chose the check mark here I I love that so much to see all these I I love that so much to see all these I I love that so much to see all these check marks and to know that I have done check marks and to know that I have done check marks and to know that I have done them yeah I love lists and I love them yeah I love lists and I love them yeah I love lists and I love ticking off ticking off ticking off lists here we

  40. lists here we lists here we go here's another one that I haven't go here's another one that I haven't go here's another one that I haven't done yet immutability of a readon file done yet immutability of a readon file done yet immutability of a readon file system create workloads with a read read system create workloads with a read read system create workloads with a read read only file system let's do it it yeah tmox set- OVI create a pod named pod OVI create a pod named pod row yeah so k row yeah so k row yeah so k run named pod row image is busy run named pod row image is busy run named pod row image is busy box yada yada and yada and then is it uh command I think you can then is it uh command I think you can then is it uh command I think you can say say say command to command to command to a a a Pod Plus and then Pod Plus and then Pod Plus and then [Music] [Music] [Music] command yeah this is so handy command yeah this is so handy command yeah this is so handy [Music] [Music] [Music] command- command ARG okay so that's really okay so that's really useful okay run pod and then command useful okay run pod and then command useful okay run pod and then command Dash Dash and then it's going to be Dash Dash and then it's going to be Dash Dash and then it's going to be sleep one day one

  41. sleep one day one sleep one day one day and then oh yal dry run is client day and then oh yal dry run is client day and then oh yal dry run is client and save that in po. and save that in po. and save that in po. Yo and it needs to be ran in the name Yo and it needs to be ran in the name Yo and it needs to be ran in the name space Sun hey Why didn't it um do a dry run Sun hey Why didn't it um do a dry run that's that's weird uh okay delete pod n weird uh okay delete pod n Sun P row oh I see okay I have to do the dry row oh I see okay I have to do the dry run client stuff that needs to be done run client stuff that needs to be done run client stuff that needs to be done before the command because now before the command because now before the command because now I'm actually including that in the I'm actually including that in the I'm actually including that in the command all command all command all right right right dry run is yo now I have my pod yaml all right yo now I have my pod yaml all right names space Sun containers command sleep names space Sun containers command sleep names space Sun containers command sleep one day that is all looking

  42. one day that is all looking one day that is all looking smooth and then the container root file smooth and then the container root file smooth and then the container root file system should be read only system should be read only system should be read only and that is done and that is done and that is done by by by [Music] [Music] [Music] security security security and let me see B security context configure a security context for context configure a security context for a pod or system should be set to system should be set to true so here we have the spec security and and then read then read then read only file really or maybe it's enabled through so

  43. really or maybe it's enabled through so let's check out the API read only root file system is a read only root file system is a Boolean so that should oops Oopsy Daisy oops Oopsy Daisy so containers and so containers and so containers and then it's on the container level uhuh okay delete pod and uhuh okay delete pod and Sun Sun Sun mhm let's apply it again mhm let's apply it again mhm let's apply it again and now it was created properly so let's check it and the properly so let's check it and the validation is successful and now the the

  44. validation is successful and now the the validation is successful and now the the it enters a new one in the it enters a new one in the it enters a new one in the scenario fix existing engine X scenario fix existing engine X scenario fix existing engine X deployment to work with readon file system add an empty deer vault volume to system add an empty deer vault volume to fix fix fix this what was that again an empty deer this what was that again an empty deer this what was that again an empty deer and then read only file okay that's new to me add an empty deer okay that's new to me add an empty deer volume to fix this well let's check out the deployment this well let's check out the deployment first okay and moon edit deploy first okay and moon edit deploy first okay and moon edit deploy web 4 oh it's not even configured with 4 oh it's not even configured with readon file system yeah so oh

  45. system yeah so oh here security context read only file here security context read only file here security context read only file system is system is system is [Music] [Music] [Music] true true true [Music] okay describe pod n okay describe pod n [Music] Moon so what is the problem with this Moon so what is the problem with this one then just out of curiosity failed so the container failed so the container is failing just gives a back crash the is failing just gives a back crash the is failing just gives a back crash the back off so K logs oh okay yeah so the logs are saying I oh okay yeah so the logs are saying I can't create at cd. log because it's a can't create at cd. log because it's a can't create at cd. log because it's a root a readon file system now I get it root a readon file system now I get it root a readon file system now I get it now I get the

  46. now I get the now I get the assignment so it is trying to create a assignment so it is trying to create a assignment so it is trying to create a file but since it's a re read only f file but since it's a re read only f file but since it's a re read only f file system it's not able to to create file system it's not able to to create file system it's not able to to create it so I have to it so I have to it so I have to create an empty directory so that it's create an empty directory so that it's create an empty directory so that it's allowed to write allowed to write allowed to write there there there gotcha so then what we do is gotcha so then what we do is gotcha so then what we do is we check out Concepts and Concepts and then then then containers containers containers no isn't it concept storage here here storage volumes no just volumes no just volumes empty there and here is an example of it empty there and here is an example of it empty deer [Music] [Music] so let's edit the deployment we're going deployment we're going to go down

  47. volume mounts happens on the container volume mounts happens on the container [Music] level mount path is going to be at level mount path is going to be at C and the name can just be cach C and the name can just be cach C and the name can just be cach volume and then the volume and then the volume and then the volumes need to be on the Pod the Pod level okay so it needs to be indented one to okay so it needs to be indented one to the the the right it's right it's right it's edited so if I now describe the edited so if I now describe the edited so if I now describe the pods started the container it's working pods started the container it's working pods started the container it's working and it has the empty deer and it has the empty deer and it has the empty deer volume and if I check it now the volume and if I check it now the volume and if I check it now the validation is successful and the validation is successful and the validation is successful and the challenge is solved yay scenario done done done done done seeing

  48. scenario done done done done done seeing all these beautiful check marks oh getting I'm at the very marks oh getting I'm at the very bottom of the scenarios bottom of the scenarios bottom of the scenarios here it's actually one two three four here it's actually one two three four here it's actually one two three four more scenarios to more scenarios to more scenarios to go and let's let's start with the static go and let's let's start with the static go and let's let's start with the static manual analysis of scenario scenario um t-mo um t-mo um t-mo set- set- set- OVI I forget what the tool is that you OVI I forget what the tool is that you OVI I forget what the tool is that you need to use though it's not trivy that's for the though it's not trivy that's for the images what is the tool that they want images what is the tool that they want images what is the tool that they want me to use again me to use again me to use again oh I forget I hope I can find static forget I hope I can find static analysis analysis oh that's really bad that I

  49. analysis oh that's really bad that I forgot the name of the forgot the name of the forgot the name of the tool saying oh it's saying oh it's a manual static analysis Oh I thought it a manual static analysis Oh I thought it a manual static analysis Oh I thought it was like there is a scenario was like there is a scenario was like there is a scenario about a tool where you have to perform about a tool where you have to perform about a tool where you have to perform an analysis of the docker files and I an analysis of the docker files and I an analysis of the docker files and I forgot what the name was so I haven't forgot what the name was so I haven't forgot what the name was so I haven't done this one so you're just supposed to done this one so you're just supposed to done this one so you're just supposed to check out the docker files so I I I check out the docker files so I I I check out the docker files so I I I haven't read the the thing it's just I haven't read the thing it's just I haven't read the solution it's just saying which one of solution it's just saying which one of solution it's just saying which one of these is of app one is less secure these is of app one is less secure these is of app one is less secure that's basically what they're that's basically what they're that's basically what they're asking asking asking so let's see do I see something so let's see do I see something so let's see do I see something here if I open root here if I open root here if I open root apps app one and one and then nine here so comparing secure well this one has only one

  50. secure well this one has only one stage this is just yeah I'm so this is running as the just yeah I'm so this is running as the Ubuntu image and this one actually goes Ubuntu image and this one actually goes Ubuntu image and this one actually goes to to to Alpine they are both running as root so Alpine they are both running as root so Alpine they are both running as root so there's they're both insecure in that there's they're both insecure in that there's they're both insecure in that sense but since this is a more minimal sense but since this is a more minimal sense but since this is a more minimal image then uh that's probably the less image then uh that's probably the less image then uh that's probably the less secure secure secure one or the more secure one because one or the more secure one because one or the more secure one because Ubuntu contains more binaries and Ubuntu contains more binaries and Ubuntu contains more binaries and therefore a larger attack service so therefore a larger attack service so therefore a larger attack service so move the less secure file that will be this one because no file that will be this one because no the other one this is the Ubuntu One this is the one this is the Ubuntu One this is the less secure one so less secure one so less secure one so move this move this move this one to root one to root one to root insecure check insecure check insecure check successful perform okay so it just wants successful perform okay so it just wants successful perform okay so it just wants you to do manual analysis of these so you to do manual analysis of these so you to do manual analysis of these so analyze them analyze them analyze them yourself so move uh actually I'm going to open two t-mo uh actually I'm going to open two t-mo windows side by

  51. windows side by windows side by side CD root side CD root side CD root apps or maybe I can just do Vim diff Vim apps or maybe I can just do Vim diff Vim apps or maybe I can just do Vim diff Vim [Music] [Music] [Music] D brute D brute D brute apps app apps app apps app two okay this is a nice way to see the two okay this is a nice way to see the two okay this is a nice way to see the difference and now I just globed them difference and now I just globed them difference and now I just globed them did you see what I did Vim D and then the path and then did Vim D and then the path and then just app to Star and then I get all of just app to Star and then I get all of just app to Star and then I get all of the app two files and I get them side by the app two files and I get them side by the app two files and I get them side by side in one command really side in one command really side in one command really neat so move the last secure neat so move the last secure neat so move the last secure file well this one is running as user file well this one is running as user file well this one is running as user app user user so this is definitely more more so this is definitely more more so this is definitely more more secure this is 27 and this is 5 secure this is 27 and this is 5 secure this is 27 and this is 5 [Music] [Music] [Music] C so the 5 C1 has got to C so the 5 C1 has got to C so the 5 C1 has got to go um go um go um move root root apps app 2 and then 5 C to root apps app 2 and then 5 C to root apps app 2 and then 5 C to root insecure insecure insecure check check check done and then we're going to do the same

  52. done and then we're going to do the same done and then we're going to do the same trick for app three star go uh let's go uh let's see which one of these see which one of these see which one of these is less secure so the left secure so the left one runs a shell script with a environment with a environment variable and that is accepted to the variable and that is accepted to the variable and that is accepted to the script as a argument the right argument the right side Echo a secret token side Echo a secret token side Echo a secret token into a file it must be the right one because the it must be the right one because the echo is going to put that into the 404 so move root apps app 404 so move root apps app 3 3 3 404 to Roots

  53. 404 to Roots 404 to Roots insecure check yay fixed it scenarios and now we have only three scenarios and now we have only three left so what do you want want to do left so what do you want want to do left so what do you want want to do first s Trace that's fun close and open first s Trace that's fun close and open first s Trace that's fun close and open ports or managing packages this all ports or managing packages this all ports or managing packages this all sounds very Linux these shouldn't be too sounds very Linux these shouldn't be too sounds very Linux these shouldn't be too difficult let's do the estray full CS course all right use estray full CS course all right use estray to see which CIS calls the estray to see which CIS calls the estray to see which CIS calls the following commands following commands following commands perform first we're going to open t-o perform first we're going to open t-o perform first we're going to open t-o and set- OVI like all every all the time and set- OVI like all every all the time and set- OVI like all every all the time and then estray and then estray and then estray this okay so here we see all of the CIS this okay so here we see all of the CIS this okay so here we see all of the CIS calls that these processes calls that these processes calls that these processes do EST un name like it's not actually checking I I name like it's not actually checking I I think I can just go next so use estray think I can just go next so use estray think I can just go next so use estray to see what kind of CIS calls the cube to see what kind of CIS calls the cube to see what kind of CIS calls the cube API server process API server process API server process performs this is more performs this is more performs this is more interesting so first figuring out what interesting so first figuring out what interesting so first figuring out what the cube API server process is so that's the cube API server process is so that's the cube API server process is so that's PS Al grap PS Al grap PS Al grap API here we see API here we see API here we see the cube API server here so that's p

  54. the cube API server here so that's p the cube API server here so that's p id22 id22 id22 three and then it's three and then it's three and then it's estray um is it um is it estray P estray estray p 2 to2 three so I'm attached to that process and if I so I'm attached to that process and if I now say do a k run pod K run engine X now say do a k run pod K run engine X now say do a k run pod K run engine X images Engine images Engine images Engine X Oh I thought I would actually stream X Oh I thought I would actually stream X Oh I thought I would actually stream that that that but I did not let's let's see so let's check out the logs then of the so let's check out the logs then of the help repeated see

  55. repeated see trace a um um tempering yeah I mean trace a tempering yeah I mean trace a tempering yeah I mean trace a path could do that with path could do that with path could do that with the location of the Pod the location of the Pod the location of the Pod theoretically but I think this should be theoretically but I think this should be theoretically but I think this should be it but it but it but it's interesting that it wasn't doing it's interesting that it wasn't doing it's interesting that it wasn't doing any CIS any CIS any CIS calls as I was running a pod so let's calls as I was running a pod so let's calls as I was running a pod so let's check out what the solution was yeah I check out what the solution was yeah I check out what the solution was yeah I did did did that ah so you have to do F yeah I was that ah so you have to do F yeah I was that ah so you have to do F yeah I was thinking of it but F here we go now we thinking of it but F here we go now we thinking of it but F here we go now we see the all of the the the pro the CIS see the all of the the the pro the CIS see the all of the the the pro the CIS calls that the cube API server process calls that the cube API server process calls that the cube API server process is CW then you wait for a bit aboard and CW then you wait for a bit aboard and here we see a a bit of a here we see a a bit of a here we see a a bit of a nicer output of it so it has been doing nicer output of it so it has been doing nicer output of it so it has been doing few Texs a th5 times few Texs a th5 times few Texs a th5 times eole wait Nano sleep right it's doing a

  56. eole wait Nano sleep right it's doing a eole wait Nano sleep right it's doing a lot of things this API server of ours lot of things this API server of ours lot of things this API server of ours all right it's solved system hardening close and open solved system hardening close and open ports that's going to be net stating t-mo set- oi the superior stating t-mo set- oi the superior editing mode for the elites there's an editing mode for the elites there's an editing mode for the elites there's an unwanted process running which listens unwanted process running which listens unwanted process running which listens on Port one 123 kill the process and on Port one 123 kill the process and on Port one 123 kill the process and delete the binary all right so net stats delete the binary all right so net stats delete the binary all right so net stats Dash tulpen and I remember that because tulpen and I remember that because tulpen is the Dutch word for tulips tulpen is the Dutch word for tulips tulpen is the Dutch word for tulips that's how I've remembered that's how I've remembered that's how I've remembered it and do I see it with the naked it and do I see it with the naked it and do I see it with the naked eye not yet but if I grab for one two 3 4 here I for one two 3 4 here I see this is the see this is the see this is the process it's called process it's called process it's called app1 so PS app1 so PS app1 so PS o o o grip here is the the process and here I grip here is the the process and here I grip here is the the process and here I see that this is the see that this is the see that this is the binary so I need to delete this binary so I need to delete this binary so I need to delete this binary but first I need to K binary but first I need to K binary but first I need to K kill it's called I think the command is

  57. kill it's called I think the command is kill it's called I think the command is pill and pill and pill and then enter the process number so now it's killed if I now number so now it's killed if I now do oh it's not killed do oh it's not killed do oh it's not killed yet well then I will just do yet well then I will just do yet well then I will just do kill kill now it's now it's killed and then I will delete the killed and then I will delete the killed and then I will delete the binary RM F and then the bin app binary RM F and then the bin app binary RM F and then the bin app one done check successful challenge one done check successful challenge one done check successful challenge solved well that was easy if the ckss exam was only this then easy if the ckss exam was only this then uh I would be flying through uh I would be flying through uh I would be flying through it back to the scenarios and wow that's it back to the scenarios and wow that's it back to the scenarios and wow that's just one more left guys one more just one more left guys one more just one more left guys one more scenario left system hardening manage scenario left system hardening manage scenario left system hardening manage packages remove and stop different packages remove and stop different packages remove and stop different Services well that shouldn't be much of Services well that shouldn't be much of Services well that shouldn't be much of a problem I'm actually surprised like I I problem I'm actually surprised like I I have now gone through the entire cks have now gone through the entire cks have now gone through the entire cks course and I thought it would be really course and I thought it would be really course and I thought it would be really hard and I thought it would be very hard hard and I thought it would be very hard hard and I thought it would be very hard on the Linux level but actually in terms on the Linux level but actually in terms on the Linux level but actually in terms of of of Linux I've been doing I've done much Linux I've been doing I've done much Linux I've been doing I've done much harder things when I was building my my harder things when I was building my my harder things when I was building my my Arch Linux

  58. Arch Linux Arch Linux system uh a while back that I had for a system uh a while back that I had for a system uh a while back that I had for a daily driver for a long time like that daily driver for a long time like that daily driver for a long time like that experience is has made this so much experience is has made this so much experience is has made this so much easier but it's it's like you need to easier but it's it's like you need to easier but it's it's like you need to know Linux for the know Linux for the know Linux for the cks but I'm surprised how far I've come cks but I'm surprised how far I've come cks but I'm surprised how far I've come without any further studies on the Linux without any further studies on the Linux without any further studies on the Linux level t-x level t-x level t-x set-i set-i set-i start remove the cube bench package okay so go ahead and remove the package okay so go ahead and remove the cubench package using the default cubench package using the default cubench package using the default package manager so Pudo up up [Music] [Music] [Music] remove Cube bench okay validation okay validation successful vsftpd has been installed successful vsftpd has been installed successful vsftpd has been installed don't uninstall it just stop the service don't uninstall it just stop the service don't uninstall it just stop the service Pudo system Pudo system Pudo system CTL stop vs ftbd check done and already solved

  59. check done and already solved wow I've got I've done all of the wow I've got I've done all of the wow I've got I've done all of the scenarios for killer or um killer scenarios for killer or um killer scenarios for killer or um killer Koda and hereby my official studies for Koda and hereby my official studies for Koda and hereby my official studies for the cks are the cks are the cks are concluded concluded concluded actually I've gone through all of the actually I've gone through all of the actually I've gone through all of the material I've done all the scenarios and material I've done all the scenarios and material I've done all the scenarios and yeah there are a few ones that I need to yeah there are a few ones that I need to yeah there are a few ones that I need to repeat but I have a fair understanding repeat but I have a fair understanding repeat but I have a fair understanding of what the exam is going to be about so of what the exam is going to be about so of what the exam is going to be about so actually I'm going to be ordering my my actually I'm going to be ordering my my actually I'm going to be ordering my my my my exam this week I'm going to order my my exam this week I'm going to order my my exam this week I'm going to order it and then the next weekend I'm going it and then the next weekend I'm going it and then the next weekend I'm going to just do killer as H over and over and to just do killer as H over and over and to just do killer as H over and over and over and over over and over over and over again like I did for the cka I literally again like I did for the cka I literally again like I did for the cka I literally did it maybe eight times or something did it maybe eight times or something did it maybe eight times or something like serious two 12h hour days in one like serious two 12h hour days in one like serious two 12h hour days in one weekend of Just Killer his age and I weekend of Just Killer his age and I weekend of Just Killer his age and I could dream that exam and I I passed and could dream that exam and I I passed and could dream that exam and I I passed and I'm going to do the same for the cks so that was cool so I started this cks so that was cool so I started this stream with app armor and I was stream with app armor and I was stream with app armor and I was stumbling around a lot that was not fun stumbling around a lot that was not fun stumbling around a lot that was not fun at all so let's see if I can fix that a at all so let's see if I can fix that a at all so let's see if I can fix that a little bit more more quickly this time around tmox set- o VI start you're asked

  60. around tmox set- o VI start you're asked to verify if the following app armor to verify if the following app armor to verify if the following app armor profiles are available on node profiles are available on node profiles are available on node 01 SSH node 01 and then app 01 SSH node 01 and then app 01 SSH node 01 and then app armor armor armor status pipe that to status pipe that to status pipe that to less do we have Docker default yes we do less do we have Docker default yes we do less do we have Docker default yes we do do we have snap. LX yes we do do we have LX yes we do do we have ftpd we do not have dump and we have dump and we have ftpd no so create it should only contain ftpd no so create it should only contain ftpd no so create it should only contain these profile names that are available these profile names that are available these profile names that are available on node one so we have all of on node one so we have all of on node one so we have all of these except for ftpd and then on control plane create ftpd and then on control plane create the file Vim root profiles file Vim root profiles txt it should only contain the profile txt it should only contain the profile txt it should only contain the profile names that are available on Noe names that are available on Noe names that are available on Noe 01 so that should 01 so that should 01 so that should be all of

  61. these except for these except for ftpd save that ftpd save that ftpd save that check check check successful that took me like what 20 successful that took me like what 20 successful that took me like what 20 minutes the first time minutes the first time minutes the first time around there's an existing deployment around there's an existing deployment around there's an existing deployment named space cow in namespace Moon it named space cow in namespace Moon it named space cow in namespace Moon it should be configured to use app armor should be configured to use app armor should be configured to use app armor profile Docker default but something profile Docker default but something profile Docker default but something seems wrong sure k n Moon edit deploy seems wrong sure k n Moon edit deploy seems wrong sure k n Moon edit deploy space cow cow edit deploy space edit deploy space edit deploy space c and here it was that The c and here it was that The c and here it was that The annotation was firstly it should annotation was firstly it should annotation was firstly it should be um this this annotation should be um this this annotation should be um this this annotation should contain the container name and not contain the container name and not contain the container name and not container so down here I see the name of container so down here I see the name of container so down here I see the name of the container is the container is the container is httpd so we're going to change this to httpd and this annotation also needs to httpd and this annotation also needs to be attached on be attached on be attached on the container the container the container spec or the Pod spec I should spec or the Pod spec I should spec or the Pod spec I should say so here The Meta say so here The Meta say so here The Meta data should contain here so if I now here so if I now KNN Moon get pods it should restart and

  62. KNN Moon get pods it should restart and KNN Moon get pods it should restart and all of the pods have now been all of the pods have now been all of the pods have now been restarted and if I validate it's restarted and if I validate it's restarted and if I validate it's successful now there is an app armor successful now there is an app armor successful now there is an app armor profile at rute profile it should be profile at rute profile it should be profile at rute profile it should be referenced by name Docker engine X referenced by name Docker engine X referenced by name Docker engine X custom and change the profile if needed custom and change the profile if needed custom and change the profile if needed install it on the nodes control plane install it on the nodes control plane install it on the nodes control plane and node 01 this is where I was mocking about 01 this is where I was mocking about with this directory that had been with this directory that had been with this directory that had been created that was really created that was really created that was really annoying oh no wait no that was the annoying oh no wait no that was the annoying oh no wait no that was the audit audit audit logging actually this is just adding it logging actually this is just adding it logging actually this is just adding it to the directory and then to the directory and then to the directory and then running um parser and then you have to running um parser and then you have to running um parser and then you have to run the parser in the directory that's run the parser in the directory that's run the parser in the directory that's what I learned you can't just run a q what I learned you can't just run a q what I learned you can't just run a q parser you have to give the path where parser you have to give the path where parser you have to give the path where to run it so there's an app armor to run it so there's an app armor to run it so there's an app armor profile at root profile at root profile at root profile CD profile CD profile CD root here's the root here's the root here's the profile we're going to adjust it so the profile we're going to adjust it so the profile we're going to adjust it so the name is Docker engine x- name is Docker engine x- name is Docker engine x- custom yes and then we are going to copy custom yes and then we are going to copy custom yes and then we are going to copy the profile the profile the profile uh to Etsy app then I will just add it to the root

  63. then I will just add it to the root directory of app armor and call it directory of app armor and call it directory of app armor and call it Docker engine X custom and then I'm going to custom and then I'm going to run app armor run app armor run app armor parser and give it the path app armor parser and give it the path app armor parser and give it the path app armor D and if I now do app D and if I now do app D and if I now do app armor armor armor status and then grab for engine status and then grab for engine status and then grab for engine X our Docker engine X custom is X our Docker engine X custom is X our Docker engine X custom is there so I'm going to do the same let's see clear SCP this file to node let's see clear SCP this file to node 01 and that directory that has directory that has been uh transferred now been uh transferred now been uh transferred now SSH node one and then app one and then app armor parser and then give it the app armor D and then give it the app armor D directory and then up armor directory and then up armor directory and then up armor status grab engine X here we go check it status grab engine X here we go check it status grab engine X here we go check it and it's done what what was that five

  64. and it's done what what was that five and it's done what what was that five minutes less than five minutes I can do minutes less than five minutes I can do minutes less than five minutes I can do it I just have to get it get the it I just have to get it get the it I just have to get it get the practice so I've learned a lot today practice so I've learned a lot today practice so I've learned a lot today I've learned I've learned I've learned these were good sessions these were good these were good sessions these were good these were good sessions these were good um this is why these these killer Kota um this is why these these killer Kota um this is why these these killer Kota scenarios are just invaluable so I'm so scenarios are just invaluable so I'm so scenarios are just invaluable so I'm so grateful that all of this is available grateful that all of this is available grateful that all of this is available out there it's just out there it's just out there it's just awesome it's just really awesome it's just really awesome it's just really awesome so wow I have now officially awesome so wow I have now officially awesome so wow I have now officially finished all of the finished all of the finished all of the cks um cks um cks um scenarios I'm going to be scenarios I'm going to be scenarios I'm going to be um practic practicing more and more in um practic practicing more and more in um practic practicing more and more in the coming week and I'm going to the coming week and I'm going to the coming week and I'm going to especially the network policies and especially the network policies and especially the network policies and the the rback those are the two ones the the rback those are the two ones the the rback those are the two ones that I'm going to keep working on I've that I'm going to keep working on I've that I'm going to keep working on I've gone I've become much better at them so gone I've become much better at them so gone I've become much better at them so I I am quite confident that I can do it I I am quite confident that I can do it I I am quite confident that I can do it on the on the on the exam um I've definitely practiced a lot exam um I've definitely practiced a lot exam um I've definitely practiced a lot with those so maybe I'll do another with those so maybe I'll do another with those so maybe I'll do another stream in the coming week where I stream in the coming week where I stream in the coming week where I practice those and uh yeah I feel quite practice those and uh yeah I feel quite practice those and uh yeah I feel quite quite ready guys ready for taking the quite ready guys ready for taking the quite ready guys ready for taking the killer as AG for at least so yeah I killer as AG for at least so yeah I killer as AG for at least so yeah I think I'm going to end the stream here I think I'm going to end the stream here I think I'm going to end the stream here I feel good about uh these two hours of feel good about uh these two hours of feel good about uh these two hours of practice thank you so much for tuning in practice thank you so much for tuning in practice thank you so much for tuning in and I hope to see you in the next one and I hope to see you in the next one and I hope to see you in the next one byebye

Summary

The main theme is completing a CKS study course and understanding AppArmor for container security. Key subjects include AppArmor profiles, restricting container actions, and verifying available profiles on a control plane node. The practical takeaway is learning how to identify and manage AppArmor configurations for enhanced system security.

View original episode β†—