Skip to main content
📬 Get weekly Production AI insights Practical notes on Kubernetes, AI infrastructure and platform engineering. No spam. Subscribe free
Luca Berton pointing at the Palo Alto Networks logo sign in the Amsterdam office after the Dutch Kubernetes meetup
Platform Engineering

Dutch Kubernetes Meetup at Palo Alto Networks Amsterdam

Dutch Kubernetes/Cloud Native Meetup at Palo Alto Networks Amsterdam: securing the container lifecycle with Prisma Cloud, then AI for attack and defence.

LB
Luca Berton
· 4 min read

On Thursday 16 January 2025 I spent the evening at the Dutch Kubernetes/Cloud Native Meetup, hosted at the Palo Alto Networks office in Amsterdam. It ran in two halves: a container security talk from the Prisma Cloud team, then a talk on how AI is changing both sides of cyber security. The evening started with pizza.

Luca Berton taking a selfie in the meetup room at Palo Alto Networks Amsterdam, with attendees seated in front of the screens

Settling in before the first talk.

Opening: community and what’s next

The organisers opened with the meetup’s title slide, carrying the Meetup and Cloud Native Computing Foundation logos over an Amsterdam skyline. The next slides covered related events: a Green Software Netherlands meetup, and KubeCon + CloudNativeCon Europe 2025, which was coming up on 1–4 April 2025 in London, along with a community discount code.

Two organisers opening the Dutch Kubernetes/Cloud Native Meetup in front of the title slide with the Meetup and CNCF logos

The Dutch Kubernetes/Cloud Native Meetup title slide, with the CNCF logo and Amsterdam skyline.

Prisma Cloud: from Dockerfile to running pod

The first talk was “Securing the Container Lifecycle – From Dockerfile to Running Pod in a Kubernetes Cluster” by Milan Krstic and Goran Bogojevic of the Prisma Cloud team at Palo Alto Networks.

Milan Krstic and Goran Bogojevic presenting Securing the Container Lifecycle, From Dockerfile to Running Pod in a Kubernetes Cluster, with the Prisma Cloud title slide on two screens

Milan Krstic and Goran Bogojevic with the Prisma Cloud title slide.

They started with a slide titled “Application Development: What Did Change?”, a grid covering four decades:

  • Development process: Waterfall, then Agile, then DevOps
  • Application architecture: monolithic, then N-tier, then microservices
  • Deployment and packaging: physical servers, then virtual servers, then containers
  • Application infrastructure: data centre, then hosted, then cloud

The core of the talk was one dense diagram, “Securing the Container Lifecycle”. It followed an image from the IDE to the VCS, through CI/CD and the registry, past admission control and into the running cluster. Runtime components like OpenSSL, curl, Go and Alpine sat next to the running workload. The point was that each stage gets its own check, not just one scan at the end.

After that came a live demo. It started from a deliberately suspicious Python app in a GitHub repository: it used Python’s built-in http.server and cloned a repository named “malware”. The demo then moved to the Prisma Cloud console, where the Dashboards, Inventory, Compliance and Alerts views showed the findings, including a CI vulnerability alert.

My take: the lifecycle diagram matches how I explain shift-left security to platform teams. Scanning in CI is necessary but not enough. Admission control and runtime visibility are where a policy actually stops a bad image. The tooling differs (Trivy, Kyverno, Gatekeeper or a commercial platform), but the stages are the same.

AI is everywhere, and so are the attacks

After a break, the second speaker opened with “AI is everywhere”: a slide of big consumer platform logos such as Google, Facebook and Amazon, with the question “But why?”. The next slide was “We are just at the start”.

The second speaker presenting the AI is everywhere slide to a full room at the Palo Alto Networks office

A full room for the second half of the evening.

A “How it all started” slide featured Nicholas Carlini. Then “How does it look” showed a machine learning lifecycle (preparation, training, operational deployment, output and improvement), with the matching attacks marked on it: poisoning, backdoors, input evasion, membership inference and model stealing.

The talk then split into two lists. How to use AI to attack: advanced phishing, deepfakes, binary obfuscation and botnet command. How to use AI to defend: moving from reactive to proactive, company-owned local LLMs, AI firewalls, and cloud connectors and scanners. An “AI-powered SOC” slide followed, covering vulnerability discovery, risk prioritisation and automated patching.

Slide titled How to use AI to attack, listing advanced phishing, deepfakes, binary obfuscation and botnets commanding

Slide titled How to use AI to defend, listing change from reactiveness to activeness, company-owned local LLMs, AI firewalls and cloud connectors and scanners

Attack and defence, one slide each.

The last section went further out: “Quantum computer vs normal computer”, then “Is there any hope left?” with an Alice-and-Bob photon diagram of quantum key distribution, and finally “Combining quantum and neural cryptography”.

The speaker presenting the Combining quantum and neural cryptography slide to the meetup audience

Closing on quantum and neural cryptography.

My take: “company-owned local LLMs” was the most practical item on the defence list. Teams that self-host models on their own Kubernetes clusters keep sensitive prompts and logs inside their own boundary. They also take on the same supply chain problem the first talk covered, now for model images and weights.

Wrapping up

Container security and AI security made a good pairing for one evening. The first talk mapped where controls belong in a Kubernetes delivery pipeline. The second showed how much of that pipeline thinking now applies to ML systems too. On the way out I stopped by the Palo Alto Networks sign.

Luca Berton pointing at the Palo Alto Networks logo sign in the Amsterdam office

Thanks to Palo Alto Networks for hosting the Dutch Kubernetes/Cloud Native Meetup.

Free 30-min Production AI consultation

Book Now