Skip to main content

Container Security Practices and Recommendations


References
https://success.docker.com/article/security-best-practices

Description

Aspects
The micro services running (inside Pod/ Container environment) should be having restricted access to resources and priviledges.

RBAC
Network Access
3rd Party access to system resources

Security aspects available in Kubernetes
Pod security policy  

Comments

Popular posts from this blog

Cloud based Frameworks/ Kubernetes environment

Cloud based microservice frameworks Some of open source platforms available are Swarm (Docker), Kubernetes (google), mesos, The most popular in communities and internet industry seems to be kubernetes and picking steam in telecom front as well for upcoming 5G Service based architecture. The kubernetes has the default container solution based on Rket ? but the most popular combinations are using Docker as container. Kubernetes/ an Cloud orachastrator !! Deployment automation of scaling in (zooming in/ increasing) and out (zooming out, decreasing) Network plugin available such as flannel (popular, support only IPv4), calico (support IPv4, IPv6), weavenet Kubernetes currently does not support dual stack IPv4, IPv6 inter-working etc capabilities till version 1.13 (dec 2018). Another limitation, it does not recognize the multiple interfaces in case enable to POD's for configuring services exposure and external communication till version 1.13 (dec 2018) Will be adding more...

4G embracing of network slicing concept

4G steps towards moving into world of network slicing with different options to utilize the opportunities which cloud/ virtualization market unleashing. Final destination to 5G architecture, where the network slicing is build-in with NSSF introduction in 3GPP. CUPS – Control User Place Separation of 4G network. This attempts to separate the Control and User Place at SGW/ PGW to achieve better control and resource requirements for network deployments. (e)DÉCOR – (enhanced) Dedicated Core Network allocation DÉCOR – R13 (No UE Changes, UE Usage Type parameter in Subscription Data … /// describes UE usage characteristics that enables the selection of a specific Dedicated Core Network (DCN).… MME uses it to map to DCN value. DCN selection at ENodeB Messages where it can be contained ULR (MME-> HSS) / IDR (HSS -> MME) / Reset (HSS -> MME) Authentication Information Answer (AIA – S6A) 29272 – S6A spec - If the MME or SGSN supports the Dedicated Core Netwo...

NSSF - an 5G network function to support the network slicing

NSSF - Network Slice Selector Function The 5G System architecture (3GPP TS 23.501: 5G SA; Stage 2) consists of the following network functions (NF). - Authentication Server Function (AUSF) - Core Access and Mobility Management Function (AMF) - Data network (DN), e.g. operator services, Internet access or 3rd party services - Structured Data Storage network function (SDSF) - Unstructured Data Storage network function (UDSF) - Network Exposure Function (NEF) - NF Repository Function (NRF) - Network Slice Selection Function (NSSF) ======>>> our focus - Policy Control function (PCF) - Session Management Function (SMF) - Unified Data Management (UDM) - Unified Data Repository (UDR) - User plane Function (UPF) - Application Function (AF) - User Equipment (UE) - (Radio) Access Network ((R)AN)