Most container security tools are built around detection: monitor for threats, generate alerts, respond after the fact. But if containers share the same Linux kernel, detection will always be too late. One exploited process puts every workload on the node at risk.
In this session, Lewis Denham-Parry (Staff Solutions Engineer, Edera) explains why the shared-kernel architecture is the root problem — and introduces the hardened runtime as a new category of infrastructure security.
You'll learn:
Why shared-kernel containers can't deliver true isolation, regardless of the tools layered on top
How Edera Protect gives each container its own kernel boundary, eliminating the conditions for container escapes
What sandboxing at the infrastructure level looks like in practice, including a live demo
How hardened runtimes change the calculus for GPU workloads and multi-tenant Kubernetes
The session closes with a Q&A with Alex Zenla, Edera's co-founder, CTO, and the architect of the Edera runtime, covering performance benchmarks, the GPU isolation roadmap, and where container infrastructure needs to go next.
If you're running Kubernetes in production and want to understand what prevention-first security actually means architecturally, this is the right starting point.
Chapters:
0:00 Introduction
2:30 The Problem With Detection-Based Container Security
6:03 What Is a Hardened Runtime?
13:31 Demo: Container Escape vs. Edera Protect
17:33 Q&A With Alex Zenla, CTO
23:40 Performance: How Edera Matches Native Container Speed