Sharan Rayakar, Progress Software | DevOps Experience 2022
At DevOps Experience 2022, Sharan Rayakar, principal product manager at Progress Software, explores how using Chef can help protect container and kubernetes environments by controlling misconfigurations.
Transcript
Hello everyone. My name is Sharon dryter. I am the product manager at progress.
I'm specifically responsible for compliance and Cloud security as part of the chef product line. And today I'm super excited to be speaking about the topic about how do we control misconfigurations at scale given that we have seen a tremendous exploration of devops and containers over the past few years. Let me jump into the agenda.
So we'll do a very brief introduction into chef and progress post that we will move into the current trends that we have been seeing across the Enterprises and the challenges they face in their container Journey. We'll also look into the Container specific characteristics and the challenges that these characteristics pose and the best practices that we have been advocating some of our customers while they are on their containers journey, and finally we'll also speak about you know, what is Chef's approach in securing our protecting your container and kubernetes and We can take any questions as we go along or probably we can do it towards the end as well. So a few words about progress progress has been providing the best of the products for customers in terms of helping them to develop high impact business applications.
We've been helping customers to automate the whole process of configuring deploying managing as well as scaling the applications and this is something that we've been helping our customers both across on-prem as well as cloud and that's something that we've been doing for close to 40 years now. Focus has grown through Acquisitions and one of the recent one has been that of Chef. So Chef has been Industries predominant devops and devsecops Technology leader.
We have helped drive digital transformation for many developers and Fortune 500 companies. We strive to provide our build products that help organizations deliver their software and infrastructure quickly safely as well as repeatedly. Again, we are putting an intense focus on making our tooling much more easier and you know, so that customers can consume and focus on their developer experience and have a shared Enterprise tooling.
So let's understand a little bit about how the container and the kubernetes adoption across the industry spanning out based on one of the recent report Gartner predicts that 70% of the organizations by 2023 will run containerized applications. One of the recent Cloud native Computing Foundation survey also showed that kubernetes adoption is approaching Almost 100% And it's the dominant container orchestration program close to 96% of the organizations within the survey indicated that either they are using or evaluating kubernetes technology. Containers and kubernetes adoption specifically has increased in large Enterprises and also companies leveraging or companies who are you know, working towards the managed services and package platforms are now increasingly using kubernetes and production.
It is also interesting to note that a cloud has, you know, the cloud hosted kubernetes platforms such as Amazon Azure, and Google has also been on the rise. So moving to a specific report from flexera which basically confirms the increasing adoption of container tools such as Docker and kubernetes across Cloud ecosystem what the report also highlights is the fact that you know, instead of organ, you know, instead of using kubernetes directly, you know, many of the organizations today install and manage kubernetes themselves. They use that using even they do that using technology such as you know, Susan Rancher and red hat openshift.
So that's a tremendous shift in terms of the devops. And you know how organizations are going more towards, you know, kind of building that into structure themselves. So the same flexor report also speaks about some of the trends that we've been seeing in terms of the cloud environment.
In fact what the report says that multi-cloud environment is pretty much the de facto standard today and the ways in which organizations adopt the multi-cloud strategies is also varying. Most of them are today taking a hybrid Cloud approach where they're using a corporation of four or more public clouds as well as private clouds. What is also interesting is the fact that a lot of Enterprises are now increasingly moving a lot of sensitive data into their into their Cloud environment.
So this was a you know, a complete shift few years back where organizations were very reluctant to move, you know, sensitive data beyond their firewall. So while all of this is happening what the report also suggests is that security continues to be the biggest challenge for both large as well as small Enterprises. Also many organizations are adopting a cloud for strategy where they are creating a kind of a central Cloud team or a center of excellence that provides centralized controls tools as well as the best practices for the rest of the organization.
And this really confirms that you know that we are heading into a direction wherein there is a central team that needs to parallely as well as simultaneously monitor security across the organization and they have to do that at tremendous skin. Based on one of the red hat survey, you know among the security challenges that impacts organizations misconfigurations. Are wrongly configuring the container environments standstall nearly 59% of the respondents.
They experienced a security incident due to misfigurations in their environment over the past 12 months and also half of the survey participants. In fact cited that misconfigurations would be one of the what is the security incident that they are they want to be addressed and they want to be super cautious in the future as well. Runtime security as well as the vulnerabilities.
Those are some of the other key security aspects that they are worried about. So let's try to understand why building security is so complicated in a container environment. So by now we'll have a lot of container users.
So there are specific container inherited characteristics that really add to some of the security challenges but also presence, you know, a lot of opportunities for organizations. So certainly by definition of microservices containers are incredibly minimal they are basically a single process entities and they're very much declarative in nature. They're built from images which are mission readable.
So it's easy to you know, predict and model their application behavior and you have a good understanding of what they are going to basically do from Container infrastructure is also immutable and it's constantly changing and this can be you know, a huge challenge when you try to prioritize risks or when you try to, you know, respond to any unusual behavior or security incidents or when you are trying to perform any monitoring or logging activity. So basically ensuring security at that particular scale is is super important. What is also super critical is the speed at which we try to find out and mitigate the rest of the container environment because as sooner you find out a problem the faster you can actually respond and remediate it and the sooner that you actually find out a problem.
You also can you know kind of get a kind of a real-time or near real-time view of an environment so that you can make investment decisions on where to really focus your critical resources on And as Enterprises achieve the simultaneous and quick auditing and fix your Cloud posture. You can you can grow your environment and you can scale your environment. So so basically the bottom line is that speed and scale pretty much kind of goes hand in hand.
Now due to the immutable nature that we have in the container environment many of the times you need to work with a devops teams. You need to work with the devops leadership. You need to work with your security teams.
So and and there are discussions on how to you know, really improve your posture what best practices you need to be follow and basically it's it's more of a kind of a bridging of a knowledge Gap that you need to do rather than just a quick patching that you need to do in the container environment. also, one of the important aspects is because containers are portable and they can be run in multi or hybrid scenarios easily moving some because a containers are portable and they can be run in multi or hybrid scenarios easily moving across pipeline security also needs to be portable and built much earlier in the cycle. And also the final and the most important characteristic is the fact that there are you know, a kind of multiple entities that are required to be secured in a microservices driven architecture.
You have a lot of images that are pretty much being built and deployed on a regular basis. Also, there is a whole ecosystem ranging from your cloud provider that you use the operating systems the applications the databases that you use so it's basically, you know security spanning across multiple TS So before we you know go into addressing how specific security challenges around the container environment can be solved. Let's look into some of the best practices that we Advocate to some of our customers.
So definitely the top of the list is implementation of the CIS Benchmark, which is a very key third party foundational resource that you would want to use that will really improve the configuration poster of your underlying environment, which can be your hosts. It can be your Docker containers. It can be your runtime environment.
It can be your kubernetes configuration. What is also important is to have a very strong visibility and governance free work because this is super essential for you to have that hybrid Cloud reporting which covers all of your Cloud providers your Cloud native world, you know, it covers all of your on-prem applications databases and operating system. Prioritizing risks in production environment is also something every organization needs to be aware of because as the container environment grows, especially in a hybrid and multi-cloud scenarios you we should be you know, really able to understand what are the greatest risks and where you need.
We need to kind of focus our remediation efforts on so that these limitation efforts will have the greatest impact. Finally, we cannot really, you know, emphasize more on how security built into the devops workflow is so super crucial crucial. So let's head towards you know, Chef's approach towards protecting the container and vitamins and if we take a look at the basic workflow and that the docker has outlined across a build trip and run.
We can really start to map some of the security considerations again, you can refine the security considerations based on your organization requirements and standards. So as you build and shift the images implementing scanning for your CIS benchmarks and your compliance becomes a super important aspect where you can actually, you know, fix flaws pretty much early rather than only focusing on them during the runtime. Most importantly if you can Implement enforcements such as where you can, you know block builds from progressing into the pipeline so you can you know, get a scalable control over what can be deployed in a production environment that will be you know, a super important thing.
Compliance also needs to underpin your entire pipeline. So being able to bring together a risk across not just containers but image hosts and even across any of the you know, demand function environment so that can become a very powerful capability that organizations can implement And all of this is really going to be imported at a high scale that you operate where you have hundreds and thousands of entities that you are responsible for. Now as we learned that speed and scale is key.
Let's really look into how Chef enables parallelism and enables faster execution while at the same time, you know, we enable you to scale in your Cloud native world. Now at the back end of this particular concept is our new Chef. It's the command called Chef inspect parallel, which enables you to execute multiple audit checks targeting multiple systems.
You also get a progress indicator which tells you how far you have progressed in your audit checks, which are executing parallel. Now it's also possible to integrate this command within a script as well as user input file which lists all the possible audit tricks that you want to execute in parallel. So basically you get a very developer friendly feature that you can integrate very easily within your cicd pipeline.
And finally, you also get to execute the same audit checks on different targets. You can actually perform different audit checks on the same Target as well or you can actually run, you know a subsection of your audit checks all of that in battle. So you get a customized way of using and running your panel checks.
So some of the use cases where speed and parallelism makes sense in the container security world. So for example, now you can monitor all of your Docker and the kubernetes environment apparently across a multiple, you know, multiple clouds or on-prem environments through through CIS benchmarks or any of your third-party regimes, including your internal standards. But you may have hundreds of thousands of your Docker in the kubernetes nodes.
So protecting all of that is something that can be accomplished now in a real time. So for your Docker environment, this can be something like, you know, where you want to perform checks on whether you have set your privileged access in a proper way. It can also be you know, where you want to perform a check to ensure that the host on which the docker is mounted is hardened.
It can also be to you know, check your image and build files as well as you know review your configuration parameters. From our container environment perspective, you know, the cia's Benchmark ticks would perform a whole bunch of audit checks across your master node across your birth and old configuration files. There may be checks from your kubelids policies across your role-based access as well as your network policies.
So all of that can be now executed in parallel. So you get a very real-time view of what is happening in your environment and you can dedicatedly, you know, allocate resources to fix those aspects of the container that Scanning of container images for viscarefigurations, maybe another use case where really you would like to have this particular checks done parallel, so you can make a you informed decision on which images to deploy and which wants to eliminate. So as we discussed that securing your Cloud native environment also requires you to work with various teams.
It requires you to work with devops teams. It requires you to work with devops leadership in some way. You're trying to bridge your knowledge Gap.
And if you really start the entire process of you know, how we wanted incorporate, you know, a security and compliance checks within an infrastructure towards the beginning, you know, every organization may have policies these policies can be security standards. It can be your regularity requirements and or it can be any of your internal standards. And most of these policies are written in a textual format which has to be interpreted by humans before they eventually implemented.
Now chefs approach has been basically to Define and document those particular policies as are our biggest human readable code now to get you started. What we do is we provide you with a library of best practices based on CIS or stick benchmarks. So that enables you to attain the Baseline policy adherence.
But really the biggest power of Chef license how you can extend and how you can add more flexibility to your policy and your audit checks. So Chef really enables you to you know, kind of bring together your security compliance and devops teams and all these three teams can come together. They can create they can modify and they can extend the code effect policies to fit the business needs.
Now by defining policy as code the biggest Advantage is definitely that it can be tested and using the chef's test driven development approach you can also ensure that your infrastructure and applications are policy compliant before you promote them into the production environment Chef also has been a you know, Chef also has adopted a fully integrated approach which really means it's a single tool. It's a single artifact that you would like to deploy. Now the other challenge that we also spoke about is the fact that security also needs to be portable and it has to be built pretty much early in the entire life cycle today where we look into the way our teams operate you may have your infra at the dev teams.
They actually contribute to change it goes into a pipeline it gets buzzed, but it never really gets it to the production. It gets into the security and the compliance Steve bucket who makes who make you know, a bunch of security changes through profiles and it in fact changes the way, you know, the infrastructure is provisioned. So having security and compliance review so late the cycle just before deployment, you know, kind of creates certain unnecessary bottlenecks in moving the code to production.
And what we really want is we want a single automated pipeline that enables devsecopes teams to all work together in the same Pipeline and you know kind of push the production into the code in a seamless way. Now through our policy as code approach. We could really enable all these three teams, you know, the compliance the security as well as operations teams.
To move into a Commerce Pipeline and push the production in a common page. Finally organizations today have multitude of environments with containers both on-prem as well as in the cloud. So from a chef perspective, we pretty much provide the best practices across multiple entities to start with it can be Cloud providers like AWS Azure and gcp Enterprises can also build their own custom policies on top of these best practices.
So you can perform your own chicks and your Cloud environment. We also provide you the best practices for your kubernetes parts. We also provided the best practices for your Docker environment again, based on CIS benchmarks, which can be again customized so that you can run your customized audit checks on the container environment.
Now all of these functionalities are also supported by our strong visibility and governance framework that gives you that multi-cloud reporting if you gives you that, you know easy to read filterables can't reports with very detailed view on what is going wrong. What is a code that is running behind the scenes and eventually what you can also do is take all of that information and feed it into any of your third party tools that can reach from service. Now kibana to Splunk or any of the other tools through our API technician So that brings me to the end of the session.
Hopefully this session was useful to all of you, but just to summarize a couple of key pointers that we spoke about the you know today the organizations are moving to cloud and Cloud native world, and the kubernetes adoption is increasing day by day. Securities still continues to be one of the biggest challenge and misconfigurations dominate the security challenge both in terms of what Enterprises face today as well as what they expect to be solved in the future. Now with the affordable nature that at which the containers operate speed and parallelism becomes important and we also saw how Chef enables scale and parallel execution through our Chef inspect command.
We also saw how converting the business requirements into policies requires really bridging that particular knowledge Gap and we also understood how Chef resolves that through the policy as support approach. Also having a proactive approach towards solving security by bringing together security compliance and the devops teams much earlier in the cycle is also super critical and we also saw how Chef enables that collaboration and how it allows the shift left. And finally with a multitude of things which are happening where we have multiple entities operating.
It was super important to really look at security as a whole and how you know, how we can actually gently enable security end-to-end. We also saw how Chef could provide that single window to manage and monitor all of these subjects. So with that I will pause and ask if you know and with that I'll pause and see if there are any questions, but otherwise, thanks a lot for listening in and giving me an opportunity to talk to you all.





