Secure Cloud Container Platform and Container Runtime

Abbas Kudrati, Sina Manavi, Muhammed Aizuddin Zali · 2025

This chapter explores how container operating systems (OSs) and runtimes can be hardened and securely configured alongside the capabilities provided by the Linux kernel and cloud provider. Cloud-specific OSs have emerged to address the unique requirements of cloud infrastructure. Container technologies, such as Docker and Kubernetes, have revolutionized application deployment and orchestration in the cloud. Immutable infrastructure represents one of the most significant advances in cloud OS security. Network security in cloud OSs has been reimagined through the lens of distributed computing. Container image security forms the cornerstone of container protection. The chapter delves into key considerations and best practices for hardening host OSs in container-based deployments on public cloud platforms. Container runtime hardening involves securing containers during their execution in the environments to prevent unauthorized access, malicious activities, and misconfigurations. The chapter looks at the future trends of emerging standards in cloud-native ecosystems.

Read the paper · More papers on PaperTik