Kubernetes Podcast in 2019: year-end recap

At the Kubernetes Podcast, we bring you a weekly round-up of cloud-native news, accompanied by an in-depth interview with a community member. As we publish our 50th and final episode for 2019, it’s time to look back on some of our favorite moments from the year.This year, we stepped out of the studio. We hosted a live recording at Google Cloud Next in San Francisco, as well as listener meetups at KubeCon EU in Barcelona and KubeCon NA in San Diego. There’s nothing more gratifying to us than having someone come up to you at a conference and tell you that they enjoy your show, or even ask after the family of foxes you mentioned were living in your backyard.  Our heartfelt thanks to everyone who came by, or stopped us in the hallways.Open source reaches all corners of the world, and we’ve been amazed at all the listeners who have joined the podcast community from around the globe. Every now and then we send out stickers by post: they’ve gone to dozens of countries on almost every continent. (We’re still waiting for a listener to reach out from Antarctica!) Thank you to our wonderful audience, who has let us know how much we’re helping them connect with and learn about the Kubernetes community. We are truly grateful to you for listening.Serious dedication tweeted to us from one podcast listenerWe would like to share some of our most popular episodes from 2019:Kubernetes Failure Stories, with Henning Jacobs (episode 38): To have the best chance for success, it helps to learn from failures. After experiencing some of his own, Henning was inspired to start collecting the failure stories of others.Ingress, with Tim Hockin (episode 41): A proud parent of the Kubernetes project, Tim is a 15-year Googler and designer of large parts of the Kubernetes networking and storage stack—an obvious extension of his years of work on the Linux kernel.Live at Google Cloud Next, with Eric Brewer (episode 49): In our first live show, Eric joined us to talk about his history in building infrastructure for search, the CAP theorem, and announcing Kubernetes to the world.KeyBank, with Gabe Jaynes (episode 51): Banks aren’t always terminals and mainframes. The smart ones, like KeyBank, are Kubernetes and mainframes! Gabe’s team worked with Google Cloud as a design partner.Istio 1.2, with Louis Ryan (episode 58): Louis has been working on API infrastructure and service mesh at Google for 10 years. He talked about the history of Istio, its design decisions, and its future goals.Attacking and Defending Kubernetes, with Ian Coldwater (episode 65): Learn how to protect your container infrastructure from Ian: they are paid to attack it, and a popular conference speaker on the topic.CRDs, API Machinery and Extensibility, with Daniel Smith (episode 73): Another long-time Kubernetes contributor, Daniel joined the project before it was open-sourced, and leads both the open-source and Google teams who build CRDs and other extensibility features.Kubernetes 1.17, with Guinevere Saenger (episode 83): Our penultimate episode for the year is an interview with the Release Team lead for the new Kubernetes 1.17. Learn how Guinevere went from being a concert pianist to a software engineer and leading a team of over 30 to produce the final Kubernetes release of 2019.If you have a break over the holidays, why not subscribe and enjoy one episode or many?  For those who can’t listen, or prefer not to, we also offer a transcript of each episode on its page at kubernetespodcast.com.We’re going to take a two-week break over the holiday period, but we’ll be back in your ears in January!
Quelle: Google Cloud Platform

Accelerate GCP Foundation Buildout with automation

We know from working with customers that starting your cloud journey can be daunting. Fortunately, there are a variety of formal options to help you on your way, such as engaging trusted advisors in the Google Cloud Professional Services Organization or one of the many partners in the Google Cloud universe.To further accelerate your cloud journey, we recently released the Cloud Foundation Toolkit, templates that will help you rapidly build a strong cloud foundation according to best practices.The Cloud Foundation Toolkit provides a series of reference templates built by the Google Cloud Professional Services team with help from partners, and with a focus on foundational elements of Google Cloud Platform. These modules are available for both the popular Terraform infrastructure-as-code framework, as well as our own Cloud Deployment Manager: The Deployment Manager Cloud Foundation Toolkit repository is a monorepo with a large number of templates available for developer reference.Cloud Foundation Toolkit Terraform modules are available on a dedicated GitHub organization and also available through the Terraform module registry. The modules can be used together or independently.The templates themselves are entirely open source and available freely on GitHub. Top Cloud Foundation Toolkit modulesThe Cloud Foundation Toolkit already includes about 60+ Terraform modules and 50+ Deployment Manager modules (and counting). Below are some of the most popular and fundamental GCP components according to GitHub repo stars and watches to get you started:Project Factory for Deployment Manager or Terraform: Create opinionated GCP projects with Shared VPC, IAM, API enablement, etc.IAM for Deployment Manager or Terraform: Manage IAM roles non-destructively across multiple resourcesNetworks for Deployment Manager or Terraform: Declaratively create and manage VPC networking in GCPGKE for Deployment Manager or Terraform: Create secure and well-configured Kubernetes clusters.Getting startedTo get started with using the Cloud Foundations Toolkit, first you need to understand Terraform or Deployment Manager. Then, to start using the toolkit itself, check out the Project Factory and GCP Folders modules. Please watch this quick demo to learn more about the Deployment Manager integration, or this video to learn how to use Cloud Foundations Toolkit with Terraform. Be sure to watch/star your favorite Cloud Foundation Toolkit repos and provide feedback by raising issues in their respective repositories.
Quelle: Google Cloud Platform

Session Manager ist jetzt direkt über die Amazon EC2-Konsole verfügbar

Sie können jetzt AWS Systems Manager Session Manager verwenden, um direkt über die Amazon EC2-Konsole eine sichere Verbindung zu Ihren Amazon EC2-Instances herzustellen. Session Manager bietet der ausgewählten EC2 Linux- oder Windows-Instance eine sichere browserbasierte interaktive Shell, die autorisierten Benutzern zusätzliche Flexibilität bietet, um schnell eine Verbindung über die Amazon EC2- oder AWS Systems Manager-Konsolen herzustellen. 
Quelle: aws.amazon.com

Amazon Textract ist jetzt PCI DSS-zertifiziert und extrahiert noch mehr Daten aus Tabellen und Formularen

Amazon Textract ist ein Machine Learning-Service, mit dem Sie mithilfe unserer DetectText- oder AnalyzeDoc-APIs einfach und schnell Text und strukturierte Daten wie Tabellen und Formulare abrufen können, ohne dass eine benutzerdefinierte Konfiguration oder Vorlagen erforderlich sind. Ein Vorteil eines verwalteten Services wie Amazon Textract besteht darin, dass Kunden von einer kontinuierlichen Verbesserung im Laufe der Zeit profitieren. Wir freuen uns, Ihnen heute mitteilen zu können, dass Amazon Textract jetzt PCI DSS-zertifiziert ist. Dies bedeutet, dass Sie Amazon Textract jetzt für alle Workloads verwenden können, für die der PCI-DSS-Informationssicherheitsstandard (PCI = Payment Card Industry Data Security Standard) erforderlich ist, z. B. für Karteninhaberdaten (CHD) oder vertrauliche Authentifizierungsdaten (SAD). Ebenfalls ab heute hat AWS eine Reihe von Qualitätsverbesserungen eingeführt, mit denen Amazon Textract für unsere Tabellen- und Formularfunktionen noch genauer wird. 
Quelle: aws.amazon.com

TakingOpenShift’s Security for Containerized Applications to the next level with Aqua

The Red Hat OpenShift Container Platform has a number of built-in security capabilities. Aqua provides an additional layer of security in development and protects containerized applications in runtime. Aqua recently developed a Kubernetes Operator that was successfully tested and validated by Red Hat OpenShift standards for integration and supportability. Aqua completed technical validations to become a Red Hat OpenShift Certified Operator, allowing our joint customers to deploy Aqua seamlessly on the OpenShift platform. 
One key differentiator of OpenShift Container Platform is that it allows users to leverage image streams when building environments using different registries.
Install, Deploy, and Check
You can use OperatorHub embedded for Red Hat OpenShift to download Aqua’s Operator. After installing the Aqua Operator and logging on to the Aqua Command Center, you can deploy the Aqua Enforcer container through a Daemonset. This helps to confirm that Aqua Enforcer runs on worker nodes in the OpenShift cluster.
What are Image Streams?
In an earlier Aqua blog, we spoke at length about image streams. Image Streams are an abstraction layer that provides mapping between image stream tags and actual images stored either in the internal OpenShift registry or in any external registry. Image streams can also be seen as pointers to actual images. A single image stream may consist of multiple tags, each of them pointing to an image from a different registry. 
Red Hat’s OpenShift Container Platform allows users to build environments that work more efficiently for large and diversified setups, by using Image Streams instead of regular images when building and deploying applications. From a security perspective, this requires a different approach for tracking security issues that should work natively with OpenShift. 
Once created, image streams can be referenced by all deployments and builds within the same project and used just like a regular image without making any special configurations to support it.  
The Aqua platform automatically discovers and connects to the image stream engine, providing the same experience and feature set as when scanning regular images from regular registries. 
Automating the Mundane
Aqua recently built a RHEL-based Operator to automate the maintenance of mundane operational duties. This makes the use of Aqua’s Cloud Native Security Platform (CSP), particularly the deployment and scanning pieces, more seamless.
When deploying Aqua CSP, you can leverage the Operator as an alternative to a deployment that uses a Helm chart or large, complicated YAML files. The Operator only requires one YAML file to deploy the Aqua infrastructure components, and another YAML file to deploy Aqua Enforcers in your production environment.
The Aqua Operator can also be configured to manage the Aqua Scanner container and scale it automatically when more resources are needed.  You can configure the minimum and maximum number of scanners you would like the Operator to deploy. You can even decide how many images you would like to allocate per scanner.  For example, if you have one scanner deployed, 500 images in your scan queue, and your maximum number of scanners is configured to 5, you’ll have 5 Aqua Scanners scaled automatically to scan all 500 images.
Aqua’s OpenShift certified operator is also available to deploy through the OpenShift console and OperatorHub.io.
OpenShift Hardening Made Easy
Kubernetes CIS benchmarks were designed to check security configurations before running Kubernetes. Red Hat took this opportunity to create a hardening guide of its own to determine if various parts of the CI pipeline were configured correctly. Aqua took this hardening guide and put it directly into their product. With this guide, you can automatically check and run tests to see if the clusters are configured correctly according to Red Hat’s guidelines.
In the image below, you can see a list of failures, warnings, pauses, and info. You can drill down for more information.
Collaboration and Innovation
Becoming a Red Hat Certified Technology Partner was a significant step in our continued work with OpenShift. Among other developments, the Aqua Operator allows OpenShift customers to scale Aqua runtime protection components more easily and handle a large number of Aqua Enforcers automatically. This capability, coupled with image streams and OpenShift hardening, extends OpenShift’s security capabilities and contributes to upgrading enterprises’ security posture.
 
The post TakingOpenShift’s Security for Containerized Applications to the next level with Aqua appeared first on Red Hat OpenShift Blog.
Quelle: OpenShift