
Brian Andrzejewski -- Containers Again
Om avsnittet
Containers make deployment repeatable, but insecure images, excessive privileges, and unmanaged secrets can travel with them. Brian Andrzejewski shares lessons from introducing containers in a government environment and developing a more deliberate security approach. He explains why early choices such as SSH access need reconsideration, how orchestration changes operations, and why teams need policies for the images they trust. Chris and Robert explore running without unnecessary privileges, read-only filesystems, vulnerability checks, and the difference between protecting the container infrastructure and the application inside it. Brian also discusses secrets, maturity models, and the role of benchmarks and guidance. The conversation offers a practical progression from experimenting with Docker to operating containers with consistent controls, visible dependencies, and a plan for ongoing maintenance.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Brian Andrzejewski:
→ Brian Andrzejewski on LinkedIn
Mentioned in this episode:
→ Docker
→ Docker Hub
→ CIS Docker Benchmark
→ NIST SP 800-190 — Application Container Security Guide
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Container security with Brian Andrzejewski
00:46 Brian’s security origin story
03:33 Introducing containers in a government environment
05:33 SSH access and disposable containers
06:28 Moving toward orchestration
07:47 Policies for trusted container images
11:30 Privileges and read-only filesystems
12:55 A maturity model for container security
16:43 Dependency inventory and CVE checks
17:56 Rebuilding and checking running containers
19:53 Application security inside containers
22:32 Handling secrets
23:36 Lessons for teams getting started
26:43 Benchmarks and resources
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.