The presentation discusses the use of GitOps and declarative policy engines to automate and customize Kubernetes security settings.
- Hardening pod runtime configuration has a new and friendlier model that replaces PSP and Arbuck.
- Port security standards and admission controllers can be highly customized to meet specific needs.
- Using GitOps and declarative policy engines can automate the entire security model and shift the burden leftward to developers.
- The Git repository can still be used as the source of truth for policies even in a distributed environment.