VRT-220 · Virtualization & Containers
Container Security & seccomp
Making containers a real security boundary rather than an organisational one.
Who this course is for
Security-minded platform engineers who need containers to be a real security boundary — and must be able to say exactly which attacks a hardened configuration stops, which it does not, and why.
Prerequisites
Course outline
Day 1 — Privilege in containers
- Capabilities: what the ones containers actually hold allow
- Bounding sets, ambient capabilities and the exec-time transformation
- no_new_privs and the privilege escalation rules
- Dropping privilege correctly: image design and runtime flags
- Privileged containers and what --privileged really grants
Day 2 — seccomp and syscall filtering
- seccomp-bpf: the BPF filter the kernel applies per syscall
- The default runtime profile: what it blocks and the reasoning
- Writing and testing custom profiles from observed syscalls
- User namespaces as an isolation boundary — and their kernel attack surface
- LSM interaction: AppArmor and SELinux under containers
Day 3 — Escapes and detection
- The escape classes: kernel exploits, misconfiguration, leaked sockets and mounts
- Runtime detection with eBPF-based syscall monitoring
- Auditing a runtime configuration against the threat you actually face
- Hardening end to end: capabilities, seccomp, userns, read-only rootfs
- Measuring what hardening costs in compatibility and performance
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: map a container's effective privilege with capsh and /proc/self/status, then strip it to what the workload demonstrably needs
- Lab: write a seccomp profile for a real workload by tracing its syscalls, then iterate from EPERM failures to a minimal allowlist
- Lab: run a workload rootless with user-namespace remapping and verify that container-root maps to an unprivileged host UID
- Lab: replay a known escape-class misconfiguration in a lab container and catch it with runtime syscall monitoring
- Lab: produce a fully hardened runtime configuration — capabilities, seccomp, userns, read-only rootfs — and document what each layer stops
Capstone project
Harden a real workload end to end and then attack it: build the layered configuration (dropped capabilities, a workload-specific seccomp profile, user namespace remapping, read-only rootfs), run a supplied set of escape-class probes against it, and record which each layer blocks and which get through. The deliverable is the hardened configuration, the probe results, and a written assessment of the residual risk — the same document your security team will ask you for.
What you leave with
- A precise, evidence-based view of container privilege — no hand-waving about 'isolated'
- seccomp profile authoring from observed syscall behaviour
- User namespace remapping as a working skill
- Runtime detection experience with eBPF-based tooling
- A repeatable hardening checklist with documented residual risk
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Security-minded platform engineers who need containers to be a real security boundary — and must be able to say exactly which attacks a hardened configuration stops, which it does not, and why. It sits at advanced level within the Virtualization & Containers track.
What do I need to know already?
Specific prerequisites for this course: VRT-201/VRT-210 or equivalent container internals; Linux privilege model (UIDs, capabilities) basics; Some exposure to syscall filtering helpful. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 22 Nov – 24 Nov 20263 full days | RiyadhIn person · KAFD Conference Centre | 10 of 14 | SAR 8,100until 23 Oct | ||
| 22 Nov – 24 Nov 20263 full days | Kuwait CityIn person · Al Hamra Tower | 5 of 14 | KWD 670until 23 Oct | ||
| 29 Nov – 1 Dec 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 10 of 14 | OMR 830until 30 Oct | ||
| 6 Dec – 13 Dec 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 14 of 20 | US$1,580until 6 Nov | ||
| 7 Dec – 9 Dec 20263 full days | OttawaIn person · Kanata North Tech Park | 5 of 14 | CAD 2,930until 7 Nov | ||
| 7 Dec – 9 Dec 20263 full days | TorontoIn person · MaRS Discovery District | 10 of 14 | CAD 2,930until 7 Nov | ||
| 7 Dec – 14 Dec 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 3 of 20 | US$1,580until 7 Nov | ||
| 14 Dec – 16 Dec 20263 full days | LondonIn person · Shoreditch Works | 5 of 14 | GBP 1,680until 14 Nov | ||
| 14 Dec – 21 Dec 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 8 of 20 | US$1,580until 14 Nov | ||
| 21 Dec – 23 Dec 20263 full days | BerlinIn person · Factory Görlitzer Park | 10 of 14 | EUR 1,990until 21 Nov |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Virtualization & Containers
VRT-1014 days
KVM Internals
How Linux becomes a hypervisor: vCPU execution, memory virtualisation and the QEMU relationship.
Practitioner-taught
SAR 12,000Next 18 Oct
VRT-1103 days
VFIO & Device Passthrough
Giving a guest direct access to real hardware — the mechanism behind GPU passthrough.
Practitioner-taught
SAR 9,000Next 15 Nov
VRT-1203 days
virtio Device Drivers
The paravirtualised device model: virtqueues, transports and writing a virtio driver.
Practitioner-taught
SAR 9,000Next 1 Nov
VRT-2013 days
Namespaces & cgroups from Scratch
Build a container by hand with the primitives, so the abstraction stops being magic.
Practitioner-taught
SAR 7,880Next 8 Nov
VRT-2103 days
Container Runtimes & the OCI Spec
What runc, containerd and the OCI specifications actually define, and how images become running processes.
Practitioner-taught
SAR 7,880Next 18 Oct