DevConf.US 2025

Boaz Michaely

Boaz is a diversified product management professional with more than 20 years of experience in security, application development and infrastructure solutions. At Red Hat, Boaz focuses on the Red Hat Advanced Cluster Security product, based on the open source Stackrox.io project.
Prior to joining Red Hat, Boaz held senior product management roles at CyberArk, Trilio and Dell EMC.
His personal Interests include playing live music and chess.

Email: Boaz.Michaely@redhat.com
LinkedIn: https://www.linkedin.com/in/boazmichaely/


Job title

Product Manager, ACS

Company or affiliation

Red Hat


Session

09-19
13:00
35min
The 10 steps of Container Security: It's not that hard !
Boaz Michaely

Congratulations,

You’ve successfully deployed and tightly configured the most secure Kubernetes platform on the planet.

Now, the question is: How can your team achieve a secure posture for the container workloads themselves?

This talk provides a practical guide at using open source Stackrox ( Red Hat ACS) to secure containers throughout their lifecycle: Build, Deploy and Runtime. We will focus on security policies and dive into specific controls.

By the end of this session you will understand:

  • The 10 essential security risk areas throughout the container's lifecycle
  • How to mitigate each risk using Stackrox
  • The kind of controls that can be enforced through Stackrox’s security policies
  • The distinctions between Stackrox policies for Build, Deploy and Runtime phases, and why we use Deploy type policies during the Build phase
  • The enforcement and remediation actions you can take at each step
Security and Compliance
106 (Capacity 45)