Skip to content

codebytes/container-security

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

12 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Guardians of the Container Galaxy: Defending the Cosmic Cluster

This repository contains a pragmatic container security framework mapped onto a memorable "Guardians of the Galaxy" crew metaphor. Each character archetype represents a critical defensive layer—supply chain integrity, runtime behavioral detection, zero‑trust networking, and observability—to help teams remember and implement comprehensive container security practices.

Slides

Slides can be found at chris-ayers.com/container-security

Demos

Hands-on walkthroughs live under demos/ for each Guardian archetype:

  1. demos/1-policy-guardrails/Star-Lord: Kyverno + Cosign admission enforcement
  2. demos/2-supply-chain-trust/Gamora: SBOM, scanning, signing pipeline
  3. demos/3-image-hardening/Rocket: Dockerfile before/after with Trivy diff
  4. demos/4-runtime-detection/Drax: Falco custom rule + controlled trigger
  5. demos/5-zero-trust-networking/Groot: Deny-by-default NetworkPolicies
  6. demos/6-observability-signals/Mantis: OTEL telemetry + Falco alert correlation

Resources

Connect with Chris Ayers

Feel free to connect with Chris Ayers on social media and visit his blog for more insights on DevOps, Azure, and container security.


License

This project is licensed under the MIT License. See the LICENSE file for details.


"We are Groot." – In security terms: we are stronger as interlocked layers, not isolated tools.

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 2

  •  
  •