Seattle, WA
December 10–13, 2018
Click Here for More Information & Registration
View Venue Map
Thursday, December 13 • 1:45pm - 2:20pm
Deep Dive: Container Identity WG - Greg Castle & Michael Danese, Google

Sign up or log in to save this to your schedule and see who's attending!

Feedback form is now closed.
Over the past year the Container Identity working group has been working on a number of initiatives relating to identity in Kubernetes. These include providing a mechanism to issue scoped JWTs that can be externally validated which improves the security of identity integrations using Kubernetes service accounts, such as Hashicorp Vault. We’ve also made significant progress in providing a new mechanism to issue and mount service account identities inside the cluster that addresses a number of security and scalability issues with existing service accounts. Finally we’ve also enabled new identity integrations by exposing OIDC functionality from the Kubernetes cluster. We’ll discuss these changes, how they can be used today, and where we are headed next.

avatar for Greg Castle

Greg Castle

Kubernetes/GKE Security Tech Lead, Google
Greg is the tech lead for the Kubernetes and Google Kubernetes Engine (GKE) security team at Google. Prior to GKE, Greg worked on the Google incident response team developing open-source investigation tools, and on OS X platform hardening. His pre-Google job roles have included pentester... Read More →
avatar for Mike Danese

Mike Danese

Software Engineer, Google
Mike is a software engineer at Google. He has worked on Kubernetes and GKE for over four years and is currently the lead of the GKE Identity Team. He is a chair and TL of the Kubernetes Auth Special Interest Group. He develops and maintains authentication infrastructure in Kubernetes... Read More →

Thursday December 13, 2018 1:45pm - 2:20pm