Tuesday, April 4, 2023
Show HN: Datree (YC W20) – End-to-End Policy Management for Kubernetes https://ift.tt/virQBjk
Show HN: Datree (YC W20) – End-to-End Policy Management for Kubernetes Hi HN, I’m Shimon, the co-founder of Datree: A policy management solution for Kubernetes. We help DevOps engineers prevent misconfigurations in their Kubernetes by enforcing an organizational policy on their clusters. Engineers can define a custom policy or use one of Datree’s built-in policies, such as NIST/NSA Hardening Guide, EKS Security Best Practices, CIS Benchmark, and more. Our website is at https://datree.io and our GitHub is here: https://ift.tt/PNkcI1V This is not the first time I have shown Datree to the HN community: A little over a year ago, I posted here an earlier version of Datree (https://ift.tt/5FzCI2L). At that time, Datree consisted of a CLI tool to detect Kubernetes misconfigurations during the development process (locally or in the CI/CD), unlike the version I present today in which the enforcement happens in production. We built the CLI tool because we detected a big problem among Kubernetes operators: Misconfigurations. Kubernetes is extremely complex and flexible, which makes it very easy to poorly configure it in ways that are not secure. And indeed, we talked to dozens of Kubernetes operators who suffered from various problems, starting with failed audits, all the way to downtime in production, all because of misconfigurations. Our solution was simple: Give the developers the means to shift-left security testing during the development process with a CLI tool that can be integrated into the CI/CD. We thought this was the best way to approach the problem: It is easiest to fix misconfigurations in the development process before they are deployed to production, it prevents context-switching and relieves resources from the DevOps team. While the CLI tool was very popular among the open-source community (it got over 6000 stars on GitHub), we soon realized that CI/CD enforcement is not enough. As we talked with Datree’s users, we realized we had made a fundamental mistake: We thought of misconfiguration prevention in technical terms rather than organizational terms. Indeed, from a technical point of view, it makes sense to shift-left Kubernetes security. But when considering the organizational structure in which it takes place, it simply isn’t enough. DevOps engineers told us that they love the shift-left concept, but they simply cannot rely on the goodwill of the engineers to run a CLI tool locally or to monitor all the pipelines leading to production. They need governance, something to help them stay in control of the state of their clusters. Moreover, we realized that many companies who use Kubernetes are heavily regulated, and cannot take any chances with their security. Sure, these companies want the engineers to fix misconfigurations during development, but they also want something to make sure that no matter what, their clusters remain misconfiguration-free. Based on this understanding, we developed a new version of Datree that sits on the cluster itself (rather than in the CI/CD) and protects the production environment by blocking misconfigured resources with an admission webhook. It has a centralized policy management solution to enable governance, and native monitoring to get real-time insights into the state of your Kubernetes. I look forward to hearing your feedback and answering any questions you may have. April 4, 2023 at 10:59PM
Subscribe to:
Post Comments (Atom)
A Manual on Self-Defense Intended for Survivalists
In the state that the world is in, you need to know self defense. When the SHTF, you could be called on to have to defend yourself from some...
-
View this post on Instagram A post shared by Technikvista (@technikvista) on Jul 1, 2020 at 5:...
-
Show HN: Hubfs – File System for GitHub https://ift.tt/706qxbI March 13, 2022 at 03:09AM from Blogger https://ift.tt/Hsl0Z7U from Tumbl...
-
Cracking the Acne Code to Clearer Skin: Skin Rejuvenation with Acne-X-Factor http://bit.ly/2FV1kx2 #breakalltherules #youthwithyouep16,,#...
No comments:
Post a Comment