Kubernetes/OpenShift
|
EKS and AKS external orchestrator functionalities are now part of the new AWS and Azure cloud connector features, respectively. If you upgraded to this release, your existing EKS and AKS external orchestrators are now read-only; if you need to make changes, create a new AWS or Azure connector. For complete information, see the relevant topics under Cloud Connectors . The external orchestrator for plain-vanilla Kubernetes and OpenShift has not changed. |
Secure Workload supports automated ingestion of inventory live from a Kubernetes cluster. When an external orchestrator configuration is added for a Kubernetes/OpenShift cluster, Secure Workload connects to the cluster’s API server and tracks the status of nodes, pods and services in that cluster. For each object type, Secure Workload imports all Kubernetes labels and labels associated with the object. All values are imported as-is.
In addition to importing the labels defined for Kubernetes/OpenShift objects, Secure Workload also generates labels that facilitate the use of these objects in inventory filters. These additional labels are especially useful in defining scopes and policies.
For more information about all of these labels, see Labels Related to Kubernetes Clusters .
If enforcement is enabled on the Kubernetes nodes (enforcement agents are installed and the configuration profile enables enforcement on these agents), enforcement policies will be installed in both the nodes as well as inside the pod namespaces using the information ingested about the Kubernetes entities via this integration.
About Kubernetes on Cloud Platforms
For the following managed kubernetes services running on supported cloud platforms, this orchestrator’s functionality is provided using cloud connectors:
-
Elastic Kubernetes Service (EKS) running on Amazon Web Services (AWS)
-
Azure Kubernetes Service (AKS) running on Microsoft Azure
-
Google Kubernetes Engine (GKE) running on Google Cloud Platform (GCP)
For details about obtaining data from kubernetes clusters on cloud platforms, see the topics under Cloud Connectors .