VRT-220 · Virtualization & Containers · Advanced

Container Security & seccomp — full syllabus

Making containers a real security boundary rather than an organisational one.

Duration3 full days in person · 6 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 9,000 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

Security-minded platform engineers who need containers to be a real security boundary — and must be able to say exactly which attacks a hardened configuration stops, which it does not, and why.

Prerequisites

Course outline

Day 1 — Privilege in containers

  • Capabilities: what the ones containers actually hold allow
  • Bounding sets, ambient capabilities and the exec-time transformation
  • no_new_privs and the privilege escalation rules
  • Dropping privilege correctly: image design and runtime flags
  • Privileged containers and what --privileged really grants

Day 2 — seccomp and syscall filtering

  • seccomp-bpf: the BPF filter the kernel applies per syscall
  • The default runtime profile: what it blocks and the reasoning
  • Writing and testing custom profiles from observed syscalls
  • User namespaces as an isolation boundary — and their kernel attack surface
  • LSM interaction: AppArmor and SELinux under containers

Day 3 — Escapes and detection

  • The escape classes: kernel exploits, misconfiguration, leaked sockets and mounts
  • Runtime detection with eBPF-based syscall monitoring
  • Auditing a runtime configuration against the threat you actually face
  • Hardening end to end: capabilities, seccomp, userns, read-only rootfs
  • Measuring what hardening costs in compatibility and performance

Hands-on labs

  1. Lab: map a container's effective privilege with capsh and /proc/self/status, then strip it to what the workload demonstrably needs
  2. Lab: write a seccomp profile for a real workload by tracing its syscalls, then iterate from EPERM failures to a minimal allowlist
  3. Lab: run a workload rootless with user-namespace remapping and verify that container-root maps to an unprivileged host UID
  4. Lab: replay a known escape-class misconfiguration in a lab container and catch it with runtime syscall monitoring
  5. Lab: produce a fully hardened runtime configuration — capabilities, seccomp, userns, read-only rootfs — and document what each layer stops

Capstone project

Harden a real workload end to end and then attack it: build the layered configuration (dropped capabilities, a workload-specific seccomp profile, user namespace remapping, read-only rootfs), run a supplied set of escape-class probes against it, and record which each layer blocks and which get through. The deliverable is the hardened configuration, the probe results, and a written assessment of the residual risk — the same document your security team will ask you for.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
22 Nov – 24 Nov 20263 full days RiyadhIn person · KAFD Conference Centre 10 of 14 SAR 8,100until 23 OctSAR 9,000
22 Nov – 24 Nov 20263 full days Kuwait CityIn person · Al Hamra Tower 5 of 14 KWD 670until 23 OctKWD 740
29 Nov – 1 Dec 20263 full days MuscatIn person · Knowledge Oasis Muscat 10 of 14 OMR 830until 30 OctOMR 920
6 Dec – 13 Dec 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 14 of 20 US$1,580until 6 NovUS$1,750
7 Dec – 9 Dec 20263 full days OttawaIn person · Kanata North Tech Park 5 of 14 CAD 2,930until 7 NovCAD 3,260
7 Dec – 9 Dec 20263 full days TorontoIn person · MaRS Discovery District 10 of 14 CAD 2,930until 7 NovCAD 3,260
7 Dec – 14 Dec 20266 half-days Europe bandLive online · 09:00–13:00 CET 3 of 20 US$1,580until 7 NovUS$1,750
14 Dec – 16 Dec 20263 full days LondonIn person · Shoreditch Works 5 of 14 GBP 1,680until 14 NovGBP 1,870
14 Dec – 21 Dec 20266 half-days Americas bandLive online · 13:00–17:00 ET 8 of 20 US$1,580until 14 NovUS$1,750
21 Dec – 23 Dec 20263 full days BerlinIn person · Factory Görlitzer Park 10 of 14 EUR 1,990until 21 NovEUR 2,210

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.