data:image/s3,"s3://crabby-images/7323e/7323e8c7eee5f17bea5546856f289c2025b060ca" alt="Share on Facebook Facebook"
data:image/s3,"s3://crabby-images/bdb81/bdb812a04fe5ff7f93d62f031a76e3bdc039fe50" alt="Share on Twitter twitter"
data:image/s3,"s3://crabby-images/5655b/5655bf3f8acfc40d59c887fb87f5ad4d580298d8" alt="Share on Google+ google_plus"
data:image/s3,"s3://crabby-images/1e24e/1e24e374d7181bb8853f5f4f910cedbeaefda598" alt="Share on Linkedin linkedin"
data:image/s3,"s3://crabby-images/fd14d/fd14d77f3f185563f88787ec6c1ab23b86ad275e" alt="Share by email mail"
data:image/s3,"s3://crabby-images/14362/14362db16e86e4395bc38e45206db6d952a0be9e" alt="feather"
Meetup happened at Google Fremont.
Although there were other presentations, i could only participate the following:
1. Aqua: As there are ongoing security concerns regarding with Docker/MicroServices approaches, as a response, i see various solutions to that. After my initial bias that Aqua is YADSC(Yet-another Docker Security Scanning), i realized it has other capabilities as well. Beside the CVE scan, it has also
- Container Inspection which actively checks suspicious behaviour
- Fingerprint the image from dev to production, preventing spoofing
- Multiregistry support like ECR, GCR, Quay, JFrog…
- Anomality Detection on containers
- Prevent malicious behaviours
Demo regarding to malicious behaviour was fork-bomb
which is also known-as
:(){ :|:& };:
If you enter this command on your bash, you will see the effect, no responsibility is accepted:)
@chernymi demonstraited the effect of fork-bomb and container freezed, after we saw that Aqua can handle this anomality.
2. rktnetes: @wobscale beginned with explaining what is rkt and differentiation with docker, going deeper with Stage1-2-3 approach of rkt.
He continued pointing out the SPOF of dockerd for <1.11 and continerd for >=1.11
Finally, he started to explain rkynetes, which basically use rkt as the container runtime.
Some of the benefits can be summarized as
- There is no daemon running the containers
- Works with systemd
- runc is supported:)
- features/speed competes with kubernetes:
Official release seems to be coming with Kubernetes 1.3
As a summary, Kubernetes is creating its own ecosystem as well. Especially for the ones using GCP, as Google Container Engine is kubernetes, it makes sense to go with.