VRT-220 · Virtualization & Containers · Advanced
Container Security & seccomp — full syllabus
Making containers a real security boundary rather than an organisational one.
Who this course is for
Security-minded platform engineers who need containers to be a real security boundary — and must be able to say exactly which attacks a hardened configuration stops, which it does not, and why.
Prerequisites
- VRT-201/VRT-210 or equivalent container internals
- Linux privilege model (UIDs, capabilities) basics
- Some exposure to syscall filtering helpful
Course outline
Day 1 — Privilege in containers
- Capabilities: what the ones containers actually hold allow
- Bounding sets, ambient capabilities and the exec-time transformation
- no_new_privs and the privilege escalation rules
- Dropping privilege correctly: image design and runtime flags
- Privileged containers and what --privileged really grants
Day 2 — seccomp and syscall filtering
- seccomp-bpf: the BPF filter the kernel applies per syscall
- The default runtime profile: what it blocks and the reasoning
- Writing and testing custom profiles from observed syscalls
- User namespaces as an isolation boundary — and their kernel attack surface
- LSM interaction: AppArmor and SELinux under containers
Day 3 — Escapes and detection
- The escape classes: kernel exploits, misconfiguration, leaked sockets and mounts
- Runtime detection with eBPF-based syscall monitoring
- Auditing a runtime configuration against the threat you actually face
- Hardening end to end: capabilities, seccomp, userns, read-only rootfs
- Measuring what hardening costs in compatibility and performance
Hands-on labs
- Lab: map a container's effective privilege with capsh and /proc/self/status, then strip it to what the workload demonstrably needs
- Lab: write a seccomp profile for a real workload by tracing its syscalls, then iterate from EPERM failures to a minimal allowlist
- Lab: run a workload rootless with user-namespace remapping and verify that container-root maps to an unprivileged host UID
- Lab: replay a known escape-class misconfiguration in a lab container and catch it with runtime syscall monitoring
- Lab: produce a fully hardened runtime configuration — capabilities, seccomp, userns, read-only rootfs — and document what each layer stops
Capstone project
Harden a real workload end to end and then attack it: build the layered configuration (dropped capabilities, a workload-specific seccomp profile, user namespace remapping, read-only rootfs), run a supplied set of escape-class probes against it, and record which each layer blocks and which get through. The deliverable is the hardened configuration, the probe results, and a written assessment of the residual risk — the same document your security team will ask you for.
What you leave with
- A precise, evidence-based view of container privilege — no hand-waving about 'isolated'
- seccomp profile authoring from observed syscall behaviour
- User namespace remapping as a working skill
- Runtime detection experience with eBPF-based tooling
- A repeatable hardening checklist with documented residual risk
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 22 Nov – 24 Nov 20263 full days | RiyadhIn person · KAFD Conference Centre | 10 of 14 | SAR 8,100until 23 Oct | ||
| 22 Nov – 24 Nov 20263 full days | Kuwait CityIn person · Al Hamra Tower | 5 of 14 | KWD 670until 23 Oct | ||
| 29 Nov – 1 Dec 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 10 of 14 | OMR 830until 30 Oct | ||
| 6 Dec – 13 Dec 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 14 of 20 | US$1,580until 6 Nov | ||
| 7 Dec – 9 Dec 20263 full days | OttawaIn person · Kanata North Tech Park | 5 of 14 | CAD 2,930until 7 Nov | ||
| 7 Dec – 9 Dec 20263 full days | TorontoIn person · MaRS Discovery District | 10 of 14 | CAD 2,930until 7 Nov | ||
| 7 Dec – 14 Dec 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 3 of 20 | US$1,580until 7 Nov | ||
| 14 Dec – 16 Dec 20263 full days | LondonIn person · Shoreditch Works | 5 of 14 | GBP 1,680until 14 Nov | ||
| 14 Dec – 21 Dec 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 8 of 20 | US$1,580until 14 Nov | ||
| 21 Dec – 23 Dec 20263 full days | BerlinIn person · Factory Görlitzer Park | 10 of 14 | EUR 1,990until 21 Nov |
Book a seat, or bring this course to your team
Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.
Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.