Trivy and Tracee, Aqua Security Tools

DevOps and Docker Talk

Episode | Podcast

Date: Fri, 20 Jan 2023 09:30:00 -0500

<p>Bret is joined by Anaïs Urlichs of Aqua Security to talk container and Kubernetes security tools like trivy, kube-bench, tracee, and kube-hunter. I've been using trivy for over four years to scan for known vulnerabilities in my own container images and my clients.</p><p>We also look at tracee, a new tool that is part of a new generation of tools that use the Linux kernel eBPF feature to investigate what's happening in real time on your servers. Anaïs is great as an explainer of Kubernetes and all cloud native things, and she's the creator of the 100 days of Kubernetes tutorials on her YouTube channel where she breaks down various cloud native topics for beginners. Based on what I've learned in this show from Anaïs, I plan to change how I use trivy so that it's scanning more things and more often in my CI automation pipelines.</p><p>Streamed live on YouTube on November 3, 2022.</p><p><br /><strong>Unedited </strong><a href="https://youtu.be/vAJH-PsKG6Y"><strong>live recording</strong></a><strong> of this show on YouTube (Ep #190)</strong></p><p>★<strong>Topics★</strong><br /><a href="https://www.aquasec.com/products/open-source-projects/">Aqua Security Tools</a><br /><a href="https://www.youtube.com/c/AquaSecurityOpenSource">Aqua Security on YouTube</a><br /><a href="https://github.com/aquasecurity/trivy">Trivy</a><br /><a href="https://aquasecurity.github.io/trivy-operator/v0.5.0/operator/">Trivy-Operator</a><br /><a href="https://github.com/aquasecurity/kube-bench">kube-bench</a><br /><a href="https://github.com/aquasecurity/tracee">tracee</a><br /><a href="https://github.com/aquasecurity/kube-hunter">kube-hunter</a></p><p><strong>★Anaïs Urlichs★</strong><br /><a href="https://twitter.com/urlichsanais">Anaïs on Twitter</a><br /><a href="http://anaisurl.com">Anaïs' Newsletter</a> <br /><a href="https://www.youtube.com/c/AnaisUrlichs">Anaïs on YouTube </a><br /><a href="https://100daysofkubernetes.io">100 Days of Kubernetes</a></p><p>★<strong>Join my Community</strong>★<br />New live <a href="http://bret.courses/autodeploy"><strong>course on CI automation and gitops deployments</strong></a><br />Best coupons for my <a href="https://www.bretfisher.com/courses"><strong>Docker and Kubernetes courses</strong></a><br />Chat with us and fellow students on our Discord Server <a href="https://devops.fan/"><strong>DevOps Fans</strong></a><strong><br /></strong>Grab some merch at <a href="https://bretfisher.myspreadshop.com/"><strong>Bret's Loot Box</strong></a></p><p>Homepage <a href="https://bretfisher.com/"><strong>bretfisher.com</strong></a></p> <ul> <li>(00:00) - DDT MAIN</li> <li>(00:04) - Intro</li> <li>(00:53) - Custom intro</li> <li>(02:28) - Main show</li> <li>(02:32) - Introducing Anais</li> <li>(04:30) - Security Tools</li> <li>(04:56) - What is Aqua Security</li> <li>(06:12) - Not all security scanners are made equal</li> <li>(07:22) - What is Trivy?</li> <li>(08:01) - Misconfiguration scanning with Trivy </li> <li>(12:12) - Security vs Disruption</li> <li>(13:06) - Address vulnerabilities in the base image</li> <li>(14:11) - Question: Operator for Trivy</li> <li>(17:51) - Automating the tool</li> <li>(19:45) - Vulnerability fatigue</li> <li>(20:32) - Question: Go and No-go Criteria</li> <li>(24:13) - Tip Toe, Start Small</li> <li>(25:19) - Kube Bench</li> <li>(26:08) - Kube Hunter</li> <li>(28:09) - What is Tracee?</li> <li>(33:39) - What is the roadmap for implementing these tools?</li> <li>(39:57) - Outro</li> </ul> <br /><p><strong>Support this show and get exclusive benefits on </strong><a href="https://patreon.com/BretFisher"><strong>Patreon</strong></a><strong>, </strong><a href="https://www.youtube.com/@BretFisher"><strong>YouTube</strong></a><strong>, or </strong><a href="https://www.bretfisher.com/"><strong>bretfisher.com</strong></a><strong>!</strong></p>