Set Up Microsegmentation for Kubernetes-Based Workloads
Procedure
1 |
Install agents on Kubernetes-based workloads. Ensure that you check the requirements and prerequisites. For more information, see Kubernetes/Openshift Agents–Deep Visibility and Enforcement. Agents are automatically installed on all future workloads managed by the applicable Kubernetes service. |
2 |
Gather labels for your Kubernetes-based workloads. For more information on:
|
3 |
Create or update your scope tree based on your labels. For more information, see Scopes and Inventory. |
4 |
Create a workspace for each scope for which you want to apply policies. For more information, see Workspaces. |
5 |
Automatically discover policies for each low-level scope. For more information, see Automatic Policy Discovery. |
6 |
For more information on applicable additional options, see Platform-Specific Policies. |
7 |
Review and analyze the suggested policies. For more information, see Review and Analyze Policies. |
8 |
Iteratively discover, review, and analyze policies as needed. For more information, see Iteratively Revise Policies. |
9 |
When you are ready, approve and enforce policies for each scope. You must enable policy enforcement in the workspace and for the agents. For more information, see Enforce Policies and Enforcement on Containers. |