피드 구독

This is a guest post by Amir Kaushansky, VP product at ARMO. 

ARMO's unique security approach combined with Openshift enterprise standard results in a total hybrid secured solution. ARMO is an additional security layer for your Kubernetes workloads.  It integrates with your CI/CD pipeline, maps the workload, and creates a strong identity: workload DNA. Based on this DNA, it provides: 

  • Malware prevention, including in-memory protection and zero-day attacks prevention. 
  • Micro-Segmentation, which is defined by an easy-to-use policy and enables cross-location (e.g. on-premises to the cloud) secure connectivity.
  • Data protection,  including encryption key management. 

ARMO is certified on OpenShift 4.x and supports Universal Base Image (UBI), you can find it in the RedHat market place.

Once ARMO is installed, on your OpenShift cluster you can use the ‘cacli’ tool to define policy and manage the agent, or you can do it from the SaaS management web user interface. 

Once ARMO’s agent has signed your workload, you can define a network and/or encryption policy and create a highly resilient environment.
The below illustrates how it is done:  in case an attacker penetrates your environment (by exploiting a weak link, exploiting an operating system component or an insider), the attacker can not do any damage as data is totally encrypted and even if it is leaked, it is useless due to the encryption, communication between your workloads is encrypted using mutual TLS - which mean that the attacker cannot eavesdrop to the communication nor to establish any communication with the other signed workloads. 


저자 소개

Red Hatter since 2018, technology historian and founder of The Museum of Art and Digital Entertainment. Two decades of journalism mixed with technology expertise, storytelling and oodles of computing experience from inception to ewaste recycling. I have taught or had my work used in classes at USF, SFSU, AAU, UC Law Hastings and Harvard Law. 

I have worked with the EFF, Stanford, MIT, and Archive.org to brief the US Copyright Office and change US copyright law. We won multiple exemptions to the DMCA, accepted and implemented by the Librarian of Congress. My writings have appeared in Wired, Bloomberg, Make Magazine, SD Times, The Austin American Statesman, The Atlanta Journal Constitution and many other outlets.

I have been written about by the Wall Street Journal, The Washington Post, Wired and The Atlantic. I have been called "The Gertrude Stein of Video Games," an honor I accept, as I live less than a mile from her childhood home in Oakland, CA. I was project lead on the first successful institutional preservation and rebooting of the first massively multiplayer game, Habitat, for the C64, from 1986: https://neohabitat.org . I've consulted and collaborated with the NY MOMA, the Oakland Museum of California, Cisco, Semtech, Twilio, Game Developers Conference, NGNX, the Anti-Defamation League, the Library of Congress and the Oakland Public Library System on projects, contracts, and exhibitions.

 
Read full bio
UI_Icon-Red_Hat-Close-A-Black-RGB

채널별 검색

automation icon

오토메이션

기술, 팀, 인프라를 위한 IT 자동화 최신 동향

AI icon

인공지능

고객이 어디서나 AI 워크로드를 실행할 수 있도록 지원하는 플랫폼 업데이트

open hybrid cloud icon

오픈 하이브리드 클라우드

하이브리드 클라우드로 더욱 유연한 미래를 구축하는 방법을 알아보세요

security icon

보안

환경과 기술 전반에 걸쳐 리스크를 감소하는 방법에 대한 최신 정보

edge icon

엣지 컴퓨팅

엣지에서의 운영을 단순화하는 플랫폼 업데이트

Infrastructure icon

인프라

세계적으로 인정받은 기업용 Linux 플랫폼에 대한 최신 정보

application development icon

애플리케이션

복잡한 애플리케이션에 대한 솔루션 더 보기

Original series icon

오리지널 쇼

엔터프라이즈 기술 분야의 제작자와 리더가 전하는 흥미로운 스토리