All Episodes

January 20, 2023 40 mins

Bret is joined by Anaïs Urlichs of Aqua Security to talk container and Kubernetes security tools like trivy, kube-bench, tracee, and kube-hunter. I've been using trivy for over four years to scan for known vulnerabilities in my own container images and my clients.

We also look at tracee, a new tool that is part of a new generation of tools that use the Linux kernel eBPF feature to investigate what's happening in real time on your servers. Anaïs is great as an explainer of Kubernetes and all cloud native things, and she's the creator of the 100 days of Kubernetes tutorials on her YouTube channel where she breaks down various cloud native topics for beginners. Based on what I've learned in this show from Anaïs, I plan to change how I use trivy so that it's scanning more things and more often in my CI automation pipelines.

Streamed live on YouTube on November 3, 2022.


Unedited live recording of this show on YouTube (Ep #190)

Topics★
Aqua Security Tools
Aqua Security on YouTube
Trivy
Trivy-Operator
kube-bench
tracee
kube-hunter

★Anaïs Urlichs★
Anaïs on Twitter
Anaïs' Newsletter
Anaïs on YouTube
100 Days of Kubernetes

Join my Community
New live course on CI automation and gitops deployments
Best coupons for my Docker and Kubernetes courses
Chat with us and fellow students on our Discord Server DevOps Fans
Grab some merch at Bret's Loot Box

Homepage bretfisher.com

  • (00:00) - DDT MAIN
  • (00:04) - Intro
  • (00:53) - Custom intro
  • (02:28) - Main show
  • (02:32) - Introducing Anais
  • (04:30) - Security Tools
  • (04:56) - What is Aqua Security
  • (06:12) - Not all security scanners are made equal
  • (07:22) - What is Trivy?
  • (08:01) - Misconfiguration scanning with Trivy
  • (12:12) - Security vs Disruption
  • (13:06) - Address vulnerabilities in the base image
  • (14:11) - Question: Operator for Trivy
  • (17:51) - Automating the tool
  • (19:45) - Vulnerability fatigue
  • (20:32) - Question: Go and No-go Criteria
  • (24:13) - Tip Toe, Start Small
  • (25:19) - Kube Bench
  • (26:08) - Kube Hunter
  • (28:09) - What is Tracee?
  • (33:39) - What is the roadmap for implementing these tools?
  • (39:57) - Outro

You can also support my free material by subscribing to my YouTube channel and my weekly newsletter at bret.news!

Grab the best coupons for my Docker and Kubernetes courses.
Join my cloud native DevOps community .css-j9qmi7{display:-webkit-box;display:-webkit-flex;display:-ms-flexbox;display:flex;-webkit-flex-direction:row;-ms-flex-direction:row;flex-direction:row;font-weight:700;margin-bottom:1rem;margin-top:2.8rem;width:100%;-webkit-box-pack:start;-ms-flex-pack:start;-webkit-justify-content:start;justify-content:start;padding-left:5rem;}@media only screen and (max-width: 599px){.css-j9qmi7{padding-left:0;-webkit-box-pack:center;-ms-flex-pack:center;-webkit-justify-content:center;justify-content:center;}}.css-j9qmi7 svg{fill:#27292D;}.css-j9qmi7 .eagfbvw0{-webkit-align-items:center;-webkit-box-align:center;-ms-flex-align:center;align-items:center;color:#27292D;}


Advertise With Us

Popular Podcasts

Dateline NBC

Dateline NBC

Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com

24/7 News: The Latest

24/7 News: The Latest

The latest news in 4 minutes updated every hour, every day.

Therapy Gecko

Therapy Gecko

An unlicensed lizard psychologist travels the universe talking to strangers about absolutely nothing. TO CALL THE GECKO: follow me on https://www.twitch.tv/lyleforever to get a notification for when I am taking calls. I am usually live Mondays, Wednesdays, and Fridays but lately a lot of other times too. I am a gecko.

Music, radio and podcasts, all free. Listen online or download the iHeart App.

Connect

© 2025 iHeartMedia, Inc.