Loading…
In-person + Virtual
18-21 April
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon Europe 2023 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Central European Summer Time (UTC +2). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date." The schedule is subject to change and session seating is available on a first-come, first-served basis. 
Friday, April 21 • 11:00 - 11:35
Implementing an Auditable Access Control Strategy Using Cluster Certificate Authority Rotation - Tyler Lisowski & Kodie Glosser IBM

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.


Changes in staff and credential exposures require organizations to have an enforcable strategy to revoke and renew access to Kubernetes clusters. Cluster certificate authorities need to be rotated in addition to the downstream certificates these cluster CAs sign to implement an access renewal and revocation strategy. Certificates issued by the cluster CA including node kubelet client certificates, node kubelet server certificates, and cluster administrator certificates need to be able to be rotated in a zero downtime fashion in order to maintain availability throughout this revocation process. This talk outlines a strategy that organizations can utilize to rotate cluster CAs with zero downtime using CA cross signing. We will visually walkthrough the workflow and how certificates for individual critical cluster components change throughout the rotation process. We will touch on how cross signing enables this process to occur without any downtime to existing components running within the cluster. We will then touch on how new access can be granted to the cluster once the rotation process is complete.

Speakers
avatar for Kodie Glosser

Kodie Glosser

Software Developer, IBM
Kodie Glosser is a Software Engineering Developer at IBM. Kodie first started at IBM as a Site Reliability Engineer, monitoring and managing over 3000 OpenStack customer instances globally for 1.5 years.When IBM Cloud Kubernetes Service (IKS) launched in 2017, Kodie transitioned to... Read More →
avatar for Tyler Lisowski

Tyler Lisowski

Lead Architect, IBM
Tyler Lisowski is the lead architect of IBM Cloud Satellite. He brings Cloud technologies where clients need it with the controls they require. He optimizes how regulated clients manage global technology fleets at the edge, on premise, and in public cloud environments. He unlocks... Read More →



Friday April 21, 2023 11:00 - 11:35 CEST
D201-202 | Second Floor | Congress Centre (Elicium Building)
  Governance + Risk + Compliance (GRC)