Posts

Showing posts with the label admission control

Falco Rocks

Image
Rock Me, Amadeus? No, not this one , this one . A few years back, I came across the Falco project and, at the time, was impressed with its runtime scanning, which was less mainstream with the masses. Fast forward to today, and the adoption of microservices has exponentially increased with no end in sight. As many of us move towards the microservices of the world and increase adoption, this area becomes increasingly lucrative to the bad guys. When our platform released our Runtime and Workload Security I started migrating my workloads and adopting more and more image and container assurance controls for my private and public workflows.   Not because of one versus the other, but because of consolidation and fluidity with my workloads and sanity :). I think many of us can agree it's becoming increasingly difficult to manage where we are heading with the plethora of great specific solutions, but the tradeoff of managing and maintaining was not an option. I needed consolidation....

Guardrails for Kubernetes

Image
With Admission Control, govern all cluster operations using a central admissions controller. Easily set policies and guardrails for cluster operations using intuitive, human-readable policy language. Enforce the least privileged access rights and ensure that all images come from trusted sources.  CloudGuard   Admission Control  monitors your clusters and enforces a security baseline across an entire namespace or cluster. It can detect if your clusters do not adhere to common practices like having good labels, annotations, resource limits, or other settings. If you configure the  Admission Control  in the Prevention mode, not only it detects a breach, but also stops the unwanted action. Put the protection in place so the bad day doesn't lead to a bad workload. Keep it Real!