What I wish I knew about container security.
2025-03-31 , The Nash

Linux is the technology that underlies all of cloud native. In this talk, we will explore the vulnerabilities that bending Linux to support container technology has uncovered. We also share new and old technologies that have changed the paradigm for container security, like eBPF, and paravirtualization. Finally, we'll showcase how easy it is to adopt these technologies to secure your containerized workloads.


This talk begins with a view of how Linux was never originally designed to support the cloud native environments and workloads that we do with it every day. There have been a decade of examples of the ongoing security challenges and vulnerabilities imposed by adapting Linux to cloud native. We aim to showcase how new and old technology like eBPF and paravirtualization change the paradigm of container security and eliminate the most common vulnerabilities.

Jed Salazar started his Security and SRE journey working on Borg clusters and securing Alphabet companies at Google. He's passionate about security and SRE and spreading knowledge to benefit everyone in the community. In his free time, he enjoys trail running the mountains of Boulder, Colorado.