Scalable Runtime Integrity Protection for Helm Based Applications on Kubernetes Cluster

被引:1
作者
Gajananan, Kugamoorthy [1 ]
Kitahara, Hirokuni [1 ]
Kudo, Ruriko [1 ]
Watanabe, Yuji [1 ]
机构
[1] IBM Japan Ltd, IBM Res Tokyo, Tokyo, Japan
来源
2021 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA) | 2021年
关键词
Kubernetes; Helm; Integrity; Admission Control; CLOUD;
D O I
10.1109/BigData52589.2021.9671944
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Enterprises adopting cloud increasingly use container orchestration systems (e.g., Kubernetes) to manage applications and their configurations at scale. In Kubernetes environment, developers use package managers (e.g., Helm) for bundling, distributing, and deploying applications. These developments in cloud native applications have introduced new challenges. One of the challenges is protecting the integrity of application packages (e.g., Helm chart) deployed in a large-scale enterprise cluster. Existing tools for verifying integrity of Helm charts are limited to verify provenance and integrity of application packages. Therefore, in this work, we propose a mechanism to verify provenance and integrity of Helm charts at the cluster-side by addressing the granularity gap to verify each resource in a chart. We demonstrate how our approach successfully enforces integrity of Helm charts and evaluate the cost of integrity enforcement with a preliminary study.
引用
收藏
页码:2362 / 2371
页数:10
相关论文
共 23 条
[21]   Cloud Governance [J].
Thuraisingham, Bhavani .
2020 IEEE 13TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD 2020), 2020, :86-90
[22]   Deploying Microservice Based Applications with Kubernetes: Experiments and Lessons Learned [J].
Vayghan, Leila Abdollahi ;
Saied, Mohamed Aymen ;
Toeroe, Maria ;
Khendek, Ferhat .
PROCEEDINGS 2018 IEEE 11TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING (CLOUD), 2018, :970-973
[23]  
YAML, 2021, YAML AINT MARKUP LAN