Application & OS layer security advice & guidance - Help Wanted

Currently I’m in the process of working with AKS & to ensure that our pods are secure, I’m utilising Twistlock. Anyway, I’ve two issues/questions that I’ve created on stack exchange, one is related to JBoss & the other is related to Linux, or to be more precise, CentOS.

I’m a little stuck with both of these issues, hence why I’m seeking help here in addition to stack exchange.

  1. My JBoss question.
  2. My Linux question.

If you can provide any help or advice, it would be deeply appreciated, a part of the reason as to why I’ve not essentially copied the questions directly on to here is to save time & duplication.

Seeing as I’m neither a JBoss or Linux guru, I thought it may be best to seek advice here, if not with the JBoss part, I know that there are many Linux gurus here! :smiley:


Core technologies used:


P.S. If you’d like me to add more information on the matter, I can’t add much more than what’s been stated in my stack exchange questions since security is among our top priorities.

Also in the event that someone suggests using ‘x’, ‘y’ or ‘z’ instead of the technologies that are currently being used, it’s because this is an enterprise scale project, refactoring to that extent isn’t a feasible option at this moment in time.