Urgent.News

What's breaking now, across thousands of outlets.

More in Tech

Seccomp profiles for real workloads, not for demos

Seccomp profiles for real workloads, not for demos A seccomp profile that denies everything except the calls a container needs is one of the strongest single controls in a Kubernetes cluster.

  • Seccomp profiles limit container calls to workload requirements, not just demos.
  • Most Kubernetes clusters use overly permissive RuntimeDefault profile.
  • Custom profiles needed for threat models involving container itself, not just boundary.

More from Wednesday 7 October →