VRT-220 · Virtualization & Containers

Container Security & seccomp

Making containers a real security boundary rather than an organisational one.

Advanced 3 days in person6 half-days online Max 14 in person

Who this course is for

Security-minded platform engineers who need containers to be a real security boundary — and must be able to say exactly which attacks a hardened configuration stops, which it does not, and why.

Prerequisites

VRT-201/VRT-210 or equivalent container internalsLinux privilege model (UIDs, capabilities) basicsSome exposure to syscall filtering helpful

Course outline

Day 1 — Privilege in containers

  • Capabilities: what the ones containers actually hold allow
  • Bounding sets, ambient capabilities and the exec-time transformation
  • no_new_privs and the privilege escalation rules
  • Dropping privilege correctly: image design and runtime flags
  • Privileged containers and what --privileged really grants

Day 2 — seccomp and syscall filtering

  • seccomp-bpf: the BPF filter the kernel applies per syscall
  • The default runtime profile: what it blocks and the reasoning
  • Writing and testing custom profiles from observed syscalls
  • User namespaces as an isolation boundary — and their kernel attack surface
  • LSM interaction: AppArmor and SELinux under containers

Day 3 — Escapes and detection

  • The escape classes: kernel exploits, misconfiguration, leaked sockets and mounts
  • Runtime detection with eBPF-based syscall monitoring
  • Auditing a runtime configuration against the threat you actually face
  • Hardening end to end: capabilities, seccomp, userns, read-only rootfs
  • Measuring what hardening costs in compatibility and performance

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: map a container's effective privilege with capsh and /proc/self/status, then strip it to what the workload demonstrably needs
  2. Lab: write a seccomp profile for a real workload by tracing its syscalls, then iterate from EPERM failures to a minimal allowlist
  3. Lab: run a workload rootless with user-namespace remapping and verify that container-root maps to an unprivileged host UID
  4. Lab: replay a known escape-class misconfiguration in a lab container and catch it with runtime syscall monitoring
  5. Lab: produce a fully hardened runtime configuration — capabilities, seccomp, userns, read-only rootfs — and document what each layer stops

Capstone project

Harden a real workload end to end and then attack it: build the layered configuration (dropped capabilities, a workload-specific seccomp profile, user namespace remapping, read-only rootfs), run a supplied set of escape-class probes against it, and record which each layer blocks and which get through. The deliverable is the hardened configuration, the probe results, and a written assessment of the residual risk — the same document your security team will ask you for.

What you leave with

  • A precise, evidence-based view of container privilege — no hand-waving about 'isolated'
  • seccomp profile authoring from observed syscall behaviour
  • User namespace remapping as a working skill
  • Runtime detection experience with eBPF-based tooling
  • A repeatable hardening checklist with documented residual risk

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

Security-minded platform engineers who need containers to be a real security boundary — and must be able to say exactly which attacks a hardened configuration stops, which it does not, and why. It sits at advanced level within the Virtualization & Containers track.

What do I need to know already?

Specific prerequisites for this course: VRT-201/VRT-210 or equivalent container internals; Linux privilege model (UIDs, capabilities) basics; Some exposure to syscall filtering helpful. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
22 Nov – 24 Nov 20263 full days RiyadhIn person · KAFD Conference Centre 10 of 14 SAR 8,100until 23 OctSAR 9,000
22 Nov – 24 Nov 20263 full days Kuwait CityIn person · Al Hamra Tower 5 of 14 KWD 670until 23 OctKWD 740
29 Nov – 1 Dec 20263 full days MuscatIn person · Knowledge Oasis Muscat 10 of 14 OMR 830until 30 OctOMR 920
6 Dec – 13 Dec 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 14 of 20 US$1,580until 6 NovUS$1,750
7 Dec – 9 Dec 20263 full days OttawaIn person · Kanata North Tech Park 5 of 14 CAD 2,930until 7 NovCAD 3,260
7 Dec – 9 Dec 20263 full days TorontoIn person · MaRS Discovery District 10 of 14 CAD 2,930until 7 NovCAD 3,260
7 Dec – 14 Dec 20266 half-days Europe bandLive online · 09:00–13:00 CET 3 of 20 US$1,580until 7 NovUS$1,750
14 Dec – 16 Dec 20263 full days LondonIn person · Shoreditch Works 5 of 14 GBP 1,680until 14 NovGBP 1,870
14 Dec – 21 Dec 20266 half-days Americas bandLive online · 13:00–17:00 ET 8 of 20 US$1,580until 14 NovUS$1,750
21 Dec – 23 Dec 20263 full days BerlinIn person · Factory Görlitzer Park 10 of 14 EUR 1,990until 21 NovEUR 2,210

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Virtualization & Containers