Settings

Theme

Secure VMs for Kubernetes: Hardening Kata Containers

srcreigh.ca

2 points by srcreigh · 2 comments

Reader

1 thread
d3Xt3r

I'm curious if you've looked at a fundamentally different solution - namely, mklinux[1]? You not only skip the entire KVM/Firecracker VMM/Kata Shim/Guest Linux/Kata Agent stack which achieves your goal of reducing the attack surface, using mklinux also mitigated entire classes of vulnerabilities such as buffer overflows/out-of-bounds I/O in the virtio stack, speculative execution side-channels, SLAT bugs etc.

[1] https://multikernel.io/technology.html

  • srcreighOP

    Thanks! No haven’t heard of this. Do you have any experience deploying untrusted workloads with this tool? care to share some more info ?

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection