{"id":34766,"date":"2022-10-28T22:39:02","date_gmt":"2022-10-28T17:09:02","guid":{"rendered":"http:\/\/ismiletechnologies.com\/?p=34766"},"modified":"2022-12-12T18:23:18","modified_gmt":"2022-12-12T12:53:18","slug":"improving-organizational-security-by-adopting-zero-trust-in-kubernetes","status":"publish","type":"post","link":"https:\/\/ismiletechnologies.com\/en_us\/cloud-security\/improving-organizational-security-by-adopting-zero-trust-in-kubernetes\/","title":{"rendered":"Improving organizational security by adopting zero-trust in Kubernetes"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"34766\" class=\"elementor elementor-34766\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-413cd17 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"413cd17\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-30e6ddc\" data-id=\"30e6ddc\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c89d397 elementor-widget elementor-widget-text-editor\" data-id=\"c89d397\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\tVery recently, the White House published a memo that provides ground work for creating a zero-trust architecture for federal agencies. With new emphasis from the US government, zero-trust networking is an area that many businesses are focusing to improve their security posture. Amidst that focus, it becomes important to understand how &amp; where these principles can be applied to cloud native environment, specifically, Kubernetes cluster.\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-384f158 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"384f158\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-537d934 elementor-widget elementor-widget-heading\" data-id=\"537d934\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">The story so far\u00a0\u00a0<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-df10d96 elementor-widget elementor-widget-text-editor\" data-id=\"df10d96\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>As there is a renewed emphasis to apply zero-trust principles to Kubernetes, we need to understand that it\u2019s not a new principle, and it has been there since a while. In the early 2000s, the concept of \u201cde-perimetrization of network resources\u201d was advanced in the UK. It suggested that organizations should stop relying on the perimeter controls like network firewall for securing their applications &amp; systems. Instead, they should arrange for securing each system &amp; directly accessing them.\u00a0\u00a0<\/p><p>In the year 2014, Google published \u201cBeyondCorp: A New Approach to Enterprise Security,\u201d \u2013 it similarly looked at how enterprises can move away from <span style=\"color: #14a49c;\"><a style=\"color: #14a49c;\" href=\"http:\/\/ismiletechnologies.com\/cloud-security-managed-services\/\">network security<\/a><\/span> and ensure that users &amp; application can ensure that callers were properly authenticated &amp; authorized. Now we have this memo from the US government \u201cMoving the U.S. Government Towards Zero Trust Cybersecurity Principles\u201d \u2013 this again recommends that organizations should not depend on the network perimeter to protect their important data &amp; systems.\u00a0\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-0971c2f elementor-widget elementor-widget-template\" data-id=\"0971c2f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"template.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-template\">\n\t\t\t\t\t<div data-elementor-type=\"section\" data-elementor-id=\"36130\" class=\"elementor elementor-36130\" data-elementor-post-type=\"elementor_library\">\n\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-2e26420 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"2e26420\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;gradient&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-790d5f4\" data-id=\"790d5f4\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-aeb095f elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"aeb095f\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-b25172c\" data-id=\"b25172c\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-4f3d6ea elementor-widget elementor-widget-heading\" data-id=\"4f3d6ea\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Do an assessment of your Azure cloud security.<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-6042693 elementor-widget elementor-widget-text-editor\" data-id=\"6042693\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Have you secured your Azure cloud environment? If you are uncertain, let our security professionals audit &amp; secure your Azure environment.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-f62d1fb\" data-id=\"f62d1fb\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-cc0ffab elementor-align-center elementor-widget elementor-widget-lottie\" data-id=\"cc0ffab\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;source&quot;:&quot;external_url&quot;,&quot;source_external_url&quot;:{&quot;url&quot;:&quot;https:\\\/\\\/assets4.lottiefiles.com\\\/packages\\\/lf20_kkesf8mx.json&quot;,&quot;is_external&quot;:&quot;&quot;,&quot;nofollow&quot;:&quot;&quot;,&quot;custom_attributes&quot;:&quot;&quot;},&quot;loop&quot;:&quot;yes&quot;,&quot;play_speed&quot;:{&quot;unit&quot;:&quot;px&quot;,&quot;size&quot;:0.9,&quot;sizes&quot;:[]},&quot;lazyload&quot;:&quot;yes&quot;,&quot;link_to&quot;:&quot;none&quot;,&quot;trigger&quot;:&quot;arriving_to_viewport&quot;,&quot;viewport&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:&quot;&quot;,&quot;sizes&quot;:{&quot;start&quot;:0,&quot;end&quot;:100}},&quot;start_point&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:0,&quot;sizes&quot;:[]},&quot;end_point&quot;:{&quot;unit&quot;:&quot;%&quot;,&quot;size&quot;:100,&quot;sizes&quot;:[]},&quot;renderer&quot;:&quot;svg&quot;}\" data-widget_type=\"lottie.default\">\n\t\t\t\t\t<div class=\"e-lottie__container\"><div class=\"e-lottie__animation\"><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-5f5686c\" data-id=\"5f5686c\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5deded9 elementor-align-right elementor-mobile-align-left elementor-tablet-align-right elementor-widget elementor-widget-button\" data-id=\"5deded9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-xs\" href=\"http:\/\/ismiletechnologies.com\/azure-cloud-security-assessment-workshop\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Proceed<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-189271c elementor-widget elementor-widget-heading\" data-id=\"189271c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Applying zero-trust principles to Kubernetes\u00a0\u00a0<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-41f6b86 elementor-widget elementor-widget-text-editor\" data-id=\"41f6b86\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Now that we have a goal \u2013 reducing reliance on network perimeter controls \u2013 what are the practical steps that organizations can take to introduce zero-trust concepts into Kubernetes environment?<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-faa4bdb elementor-widget elementor-widget-heading\" data-id=\"faa4bdb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Service-to-service networking<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-442537c elementor-widget elementor-widget-text-editor\" data-id=\"442537c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>At first we need to look at the container network. By default, every Kubernetes cluster provides a flat network wherein every container can communicate directly with every other container without any restrictions. This type of container network is always treated as a \u201ctrusted\u201d network by the applications running in it, and the services don\u2019t require any authentication for requests which originate from within the network. Let\u2019s say we have a range of services connected to a cluster network which can access each other at network level. How can its security be improved? We can do so by enabling Kubernetes network policies to apply default rules to both ingress &amp; egress traffic in the cluster. Since network policies apply to workloads based on logical parameters, it can be ensured that only related workloads can communicate with each other.\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-22692dc elementor-widget elementor-widget-heading\" data-id=\"22692dc\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">User-to-service access\u00a0\u00a0<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-cc7c7db elementor-widget elementor-widget-text-editor\" data-id=\"cc7c7db\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>There\u2019s another aspect to zero-trust Kubernetes that has to be accounted for as well, this is user-to-cluster communications. Since Kubernetes does not have a provision of production-grade authentication option, external solutions will be needed to fully realize a zero-trust vision. One option would be service mesh, where user access effectively goes through some kind of proxy service before hitting the Kubernetes API, where that proxy can put controls based on things like device posture &amp; request sensitivity.\u00a0\u00a0<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9210559 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"9210559\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-31bdbe1 elementor-widget elementor-widget-text-editor\" data-id=\"31bdbe1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>It is obvious that way for most organizations is towards adopting a zero-trust approach to organizational network security. The old days when many organizations took a hardened perimeter approach with a soft interior are numbered. However, this is going to be a long process. ISmile Technologies helps you to increase the speed of your innovation for tremendous advantage with our end-to-end solutions. Being veterans in the DevOps &amp; Kubernetes, we leverage our years of hands-on experience to offer you out-of-the-box solutions to meet your business needs. At ISmile Technologies we see <span style=\"color: #14a49c;\"><a style=\"color: #14a49c;\" href=\"http:\/\/ismiletechnologies.com\/devsecops-managed-services\/\">DevOps<\/a><\/span> as a no-touch CI\/CD driven software delivery approach. An approach that believes that an integrated delivery function from requirements to production will give higher business value to customers. We help you reimagine cloud security by building it into the foundation of your company, it can meet your businesses\u2019 needs as a fully managed as-a-service model ensuring seamless compliance &amp; security.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Very recently, the White House published a memo that provides ground work for creating a zero-trust architecture for federal agencies. With new emphasis from the US government, zero-trust networking is an area that many businesses are focusing to improve their security posture. Amidst that focus, it becomes important to understand how &amp; where these principles [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":34767,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[123],"tags":[],"class_list":["post-34766","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud-security"],"_links":{"self":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts\/34766","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/comments?post=34766"}],"version-history":[{"count":7,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts\/34766\/revisions"}],"predecessor-version":[{"id":36183,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/posts\/34766\/revisions\/36183"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/media\/34767"}],"wp:attachment":[{"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/media?parent=34766"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/categories?post=34766"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ismiletechnologies.com\/en_us\/wp-json\/wp\/v2\/tags?post=34766"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}