Scalable Runtime Integrity Protection for Helm Based Applications on Kubernetes Cluster

被引:1
作者
Gajananan, Kugamoorthy [1 ]
Kitahara, Hirokuni [1 ]
Kudo, Ruriko [1 ]
Watanabe, Yuji [1 ]
机构
[1] IBM Japan Ltd, IBM Res Tokyo, Tokyo, Japan
来源
2021 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA) | 2021年
关键词
Kubernetes; Helm; Integrity; Admission Control; CLOUD;
D O I
10.1109/BigData52589.2021.9671944
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Enterprises adopting cloud increasingly use container orchestration systems (e.g., Kubernetes) to manage applications and their configurations at scale. In Kubernetes environment, developers use package managers (e.g., Helm) for bundling, distributing, and deploying applications. These developments in cloud native applications have introduced new challenges. One of the challenges is protecting the integrity of application packages (e.g., Helm chart) deployed in a large-scale enterprise cluster. Existing tools for verifying integrity of Helm charts are limited to verify provenance and integrity of application packages. Therefore, in this work, we propose a mechanism to verify provenance and integrity of Helm charts at the cluster-side by addressing the granularity gap to verify each resource in a chart. We demonstrate how our approach successfully enforces integrity of Helm charts and evaluate the cost of integrity enforcement with a preliminary study.
引用
收藏
页码:2362 / 2371
页数:10
相关论文
共 23 条
[1]  
[Anonymous], 2020, TRUSTED SERVICE IDEN
[2]  
[Anonymous], 2011, NIST SPEC PUBL
[3]  
[Anonymous], 2020, SIGNING CONTAINER IM
[4]  
[Anonymous], 2020, CONT TRUST DOCK
[5]  
[Anonymous], 2020, PORTIERIS KUBERNETES
[6]  
[Anonymous], 2020, UPD FRAM FRAM SEC SO
[7]  
[Anonymous], 2020, KUBERNETES OPERATORS
[8]  
[Anonymous], 2021, ARTIFACT HUB
[9]  
[Anonymous], 2020, SWARM MODE OVERVIEW
[10]  
[Anonymous], 2020, NOTARY SIGNING