SlideShare a Scribd company logo
Red Hat/CyberArk webinar
Jody Hunt
Director, DevOps Security
CyberArk
Vijay Arungurikai
Senior Solutions Architect
Embedded & ISV Partners, Red Hat
F16625-200131
The world’s leading provider
of open source enterprise IT solutions
2
*Red Hat client data and Fortune 500 list, October 2019.
Note: Currency in U.S. dollars.
MORE THAN
90%of the
FORTUNE
500
RED HAT
use
PRODUCTS &
SOLUTIONS*
~13,815
EMPLOYEES
105+
OFFICES
40+
COUNTRIES
THE FIRST
$3
OPEN
SOURCE
COMPANY
IN THE WORLD
BILLION
From communities to enterprise
3
44
Red Hat
Enterprise Linux
Red Hat
Virtualization
Red Hat
OpenStack Platform
Red Hat
Ceph Storage
Infrastructure Software
Container Platform
Red Hat
OpenShift Container Platform
Developer Tools
Automation &
Management
Red Hat
Ansible Automation
Platform
Red Hat
Satellite
Red Hat
Insights
Red Hat
CloudForms
Middleware & Integration
Red Hat
Fuse
Red Hat
Decision Manager
Red Hat
Process Automation Manager
Application & Business processes
Red Hat
JBoss EAP
Red Hat
AMQ
Red Hat
3Scale API Mgmt
Red Hat
OpenShift Application
Runtimes
Red Hat
CodeReady
Workspace
Services
Red Hat
Learning Subscription
Red Hat
Certification
Red Hat
Consulting
Red Hat
OPEN Innovation Labs
Product Portfolio
NEW INSTALLER
PLATFORMS
STORAGE
AUTOMATION
CLOUD-NATIVE
DEV TOOLS
RHV IPI
Azure & OpenStack UPI
DNS forwarding
Kubernetes 1.17
OpenShift Serverless is GA
Helm 3 support is GA
OpenShift Pipelines is TP
Developer Console gains
monitoring & Helm features
CSI topology support
CSI Volume snapshot,
restore, clone (Tech Preview)
iSCSI PVs for internal registry
Auto image pruning in registry
OpenShift 4.4
5
6
Developer Productivity
Cluster Services
Automated Ops ⠇Over-The-Air Updates ⠇Monitoring ⠇Registry ⠇Networking ⠇Router ⠇KubeVirt ⠇OLM ⠇Helm
Kubernetes
Developer CLI ⠇VS Code
extensions ⠇IDE Plugins
Code Ready Workspaces
CodeReady Containers
Service Mesh ⠇Serverless
Builds ⠇CI/CD Pipelines
Full Stack Logging
Chargeback
Databases ⠇Languages
Runtimes ⠇Integration
Business Automation
100+ ISV Services
Platform Services Application Services Developer Services
Physical Virtual Private cloud Public cloud
OpenShift
Kubernetes
Engine
Build Cloud-Native AppsManage Workloads
Multi-cluster Management
Discovery ⠇Policy ⠇Compliance ⠇Configuration ⠇Workloads
Advanced
Cluster
Management
OpenShift
Container
Platform
Managed cloud
(Azure, AWS, IBM, Red Hat)
Red Hat Enterprise Linux & RHEL CoreOS
OpenShift Container Platform
Automated
operations
A consistent container application platform
Multi-tenant
Network
traffic control
Over-the-air
updates
Bare metal, VMware vSphere, Red Hat Virtualization, Red Hat OpenStack Platform, Amazon
Web Services, Microsoft Azure, Google, IBM Cloud
Pluggable
architecture
Monitoring
& chargeback
Secure by default
FROM YOUR DATACENTER TO THE CLOUD
7
OpenShift enables developer productivity
SPRING & JAVA™ EE MICROSERVICES FUNCTIONS
LANGUAGES DATABASES APPLICATION SERVICES
LINUX WINDOWS*
* coming soon
CODE
BUILD TEST DEPLOY
MONITORREVIEW
Self-service
provisioning
Automated
build & deploy
CI/CD
pipelines
Consistent
environments
Configuration
management
App logs &
metrics
8
Full Stack Automation (IPI) Pre-existing Infrastructure (UPI)
Bare Metal
4.4 Supported Providers
IBM Power Systems
*
* Note: Planned for an upcoming 4.3.z release on April 30th
*
Denotes new addition in OCP 4.4
9
OpenShift offers the broadest set of hybrid cloud
services
Red Hat
OpenShift
Dedicated
Managed By Red Hat
or
Customer
Managed
or
Customer
Managed
Red Hat
OpenShift
Dedicated
Managed By Red Hat
or
Customer
Managed
Red Hat
OpenShift on
IBM Cloud
or
Customer
Managed (UPI)
Customer
Managed
On-premises
Azure Red Hat
OpenShift
Jointly Managed &
Supported Jointly Engineered
10
11
Red Hat OpenShift has seen 70%+ market expansion
Red Hat OpenShift customers
● Supported on every major cloud: AWS, Azure, GCP, IBM,
AliCloud
● Broadest hybrid cloud market adoption
● 100s of ISVs supporting operators
● Expanded AI/ML focus
● 1st to market with service mesh
● 1st to market with serverless
● New CodeReady developer experience
● New security, encryption enhancements
● Integrated IBM Portfolio via CloudPaks
● ...and much more
1700+
FY 2015 FY 2016 FY 2017 FY 2018 FY 2019 FY 2020
500
0
1000
1500
2000
12
A broad ecosystem of workloads
Operator-backed services allow for a
SaaS experience on your own infrastructure
Relational DBs
NoSQL DBs
Storage
Messaging
Security
Monitoring
AI/ML
Big Data
DevOps
Operator SDK
13
Enabling everybody to write Operators
Support for Helm 3
Build Operators from Helm
v2 and v3 charts
Ansible collections
Ansible Operator supports
k8s module collection
Custom metrics
Every Operator supports
custom metric endpoints
Generate Packaging
Operator Metadata (CSV) for
OLM gets generated
Kubernetes Compatibility
Keep in sync with new
Kubernetes releases
Scorecard v2
Enable testing your
Operator in a pipeline
Do your applications use
privileged credentials?
Secrets management for Red Hat OCP
Jody Hunt, DevOps SME
14
EVERYBODY WANTS A SECURE DEVOPS FLOW, BUT…
SHIFTING SECURITY LEFT INTO DEVELOPMENT WORKFLOWS
16
Developers
DevOps
Security
Empower Security Team
• Highlight the app & tool risk
• Leverage single platform –
human/non-human solution serves all
• Security focus
• Manage security budget
Enable Developer/DevOps
• Easy to use (consume secrets)
• Prebuilt integrations
• Open source and Secretless
Free developers from security burden
• Compliance, audit requests, human creds
• Security budget
Plan Code Create Test Release Deploy Operate
THE PROBLEM WE’RE SOLVING
There are lots of places to store secrets.
But:
• Platform solutions only work for
those platforms
• Tool solutions lack security
• Most not enterprise ready
• Hard to share best-practices
• SoD not enforced
• GRC reporting is impossible
Islands of Security
Hiera DatabagsVault
IAM / KMS IAM / KMS
Home Grown
Solutions
SecretsSecrets
IAM / KMS
THE VISION WE’RE DELIVERING ON
Enterprise-Spanning Service delivered by IT Security
IaaSOn-Prem Infrastructure and Apps
(*NIX, Windows, zOS)
DevOps ToolsPaaS
Security
Solutions
IT Mgt
Software
App Servers and
Custom Apps
RPA
PAS
Consistently enforce privilege security policies for both human users and non-human identities
CENTRAL AUDIT, SECURITY POLICY, SECRETS ROTATION
Application Access Manager
Consistent, Unified Enterprise-Wide
Privileged Access Security Program
CyberArk
Vault
Multi-Persona UI
Security
Admin
Developer
/DevOps
Admin
Threat Detection
and Analytics
Credential
Providers
–
Static Apps
Agent-based
Credential
Rotation
/Policy Driven
Monitoring
and Audit
Secrets
Management
–
Dynamic
Agentless
Dynamic Access Provider (Conjur Open Source)
OCP4 Lab Architecture
Linux Host
(Azure)
Windows Hosts
(my Mac)
CyberArk Enterprise
Password Vault
Synchronizer
OCP4 Cluster
(AWS)
User
Namespaces
Lab
App
Authen
-ticator
cybrlab
Namespace
ServiceService
SECRETS ACCESS WORKFLOW
Authenticate
Access Token
Requestor
Application Access Manager
Dynamic Access Provider
Targe
t
Access per Policy
Retrieve secrets
Use secrets
Access Token
expires after 8 mins
Audited
activity
• Lab 1:
• Authenticator runs as a Sidecar
• App pulls DB creds with REST API
• App connects to DB
• Lab 2: Secrets Injection
• Leverages Summon component
• Authenticator runs as an Init container
• Summon pulls DB creds & calls app w/ creds in env vars
• App connects to DB
• Lab 3: K8s Secrets
• Authenticator runs as an Init Container
• K8s secret manifest names DB cred names
• Authenticator retrieves DB creds & dynamically patches
K8s secret w/ DB cred values
• App connects to DB
• Lab 4: Secretless Broker
• Authenticator runs as a Sidecar Container listening on
DB port
• App attempts to connect to DB on local port
• Authenticator retrieves DB creds, connects to DB,
proxies connection for app
• App connects to DB
CYBERARK OCP4 LABS
THE SECRETS LIFECYCLE TODAY
Secrets Storage
Secrets Delivery
Application
s
• Monthly DevOps Workshops (Virtual)
• “CyberArk DevOps Workshop”
• July 16th
, 1pm Eastern
• https://www.cyberark.com/devops-workshops
• CyberArk Red Hat Integrations
• www.cyberark.com/redhat
• RedHat Ecosystem for CyberArk
• access.redhat.com/containers/#/vendor/cyberark
• CyberArk AAM documentation
• docs.cyberark.com
• lower right is Dynamic Access Provider
• Conjur Open Source Resources
• Open Source Secrets Management conjur.org
• Blog conjur.org/blog
• Developer Community cyberarkcommons.org
• Secretless Broker: conjur.org/Secretless
• Enterprise Resources
• Application Access Manager
• DevOps Security
EXPLORE SECRETS MANAGEMENT AND DEVOPS SECURITY :
24
linkedin.com/company/red-hat
youtube.com/user/RedHatVideos
facebook.com/redhatinc
twitter.com/RedHat
Red Hat is the world’s leading provider of
enterprise open source software solutions.
Award-winning support, training, and consulting
services make
Red Hat a trusted adviser to the Fortune 500.
Thank you

More Related Content

What's hot (20)

PDF
Running on Amazon EKS – How Greenlight Gets Security Right
DevOps.com
 
PDF
Deliver your App Anywhere … Publicly or Privately
DevOps.com
 
PPTX
Intro to android (gdays)
Omolara Adejuwon
 
PPTX
Automate and Enhance Application Security Analysis
Carlos Andrés García
 
PPTX
Micro Focus Corporate Overview
Micro Focus
 
PPTX
Troubleshooting the Most Common Citrix Complaints for Remote Workers
eG Innovations
 
PDF
DevOps in the Real World: Know What it Takes to Make it Work
VMware Tanzu
 
PDF
DevOps for Highly Regulated Environments
DevOps.com
 
PPTX
Easily Create Scalable Automation using Selenium
Micro Focus
 
PDF
Using Collaboration to Make Application Vulnerability Management a Team Sport
Denim Group
 
PDF
Webinar–The 2019 Open Source Year in Review
Synopsys Software Integrity Group
 
PPTX
Dev opscon survey summary 2013
Alan Shimel
 
PPTX
DevOps For Everyone: Bringing DevOps Success to Every App and Every Role in y...
Siva Rama Krishna Chunduru
 
PDF
Integrating SAP into DevOps Pipelines: Why and How
DevOps.com
 
PPTX
App-First & Cloud-Native: How InterMiles Boosted CX with AWS & Infostretch
Infostretch
 
PPTX
The Developer is the New CIO: How Vendors Adapt to the Changing Landscape
Lauren Cooney
 
PDF
Managing Compliance in Container Environments
Twistlock
 
PDF
Dependency Health: Removing the Barriers to Keeping Projects in Shape
DevOps.com
 
PDF
OWASP San Antonio Meeting 10/2/20
Denim Group
 
PDF
Spring Boot & Spring Cloud on Pivotal Application Service
VMware Tanzu
 
Running on Amazon EKS – How Greenlight Gets Security Right
DevOps.com
 
Deliver your App Anywhere … Publicly or Privately
DevOps.com
 
Intro to android (gdays)
Omolara Adejuwon
 
Automate and Enhance Application Security Analysis
Carlos Andrés García
 
Micro Focus Corporate Overview
Micro Focus
 
Troubleshooting the Most Common Citrix Complaints for Remote Workers
eG Innovations
 
DevOps in the Real World: Know What it Takes to Make it Work
VMware Tanzu
 
DevOps for Highly Regulated Environments
DevOps.com
 
Easily Create Scalable Automation using Selenium
Micro Focus
 
Using Collaboration to Make Application Vulnerability Management a Team Sport
Denim Group
 
Webinar–The 2019 Open Source Year in Review
Synopsys Software Integrity Group
 
Dev opscon survey summary 2013
Alan Shimel
 
DevOps For Everyone: Bringing DevOps Success to Every App and Every Role in y...
Siva Rama Krishna Chunduru
 
Integrating SAP into DevOps Pipelines: Why and How
DevOps.com
 
App-First & Cloud-Native: How InterMiles Boosted CX with AWS & Infostretch
Infostretch
 
The Developer is the New CIO: How Vendors Adapt to the Changing Landscape
Lauren Cooney
 
Managing Compliance in Container Environments
Twistlock
 
Dependency Health: Removing the Barriers to Keeping Projects in Shape
DevOps.com
 
OWASP San Antonio Meeting 10/2/20
Denim Group
 
Spring Boot & Spring Cloud on Pivotal Application Service
VMware Tanzu
 

Similar to Securing Red Hat OpenShift Containerized Applications At Enterprise Scale (20)

PDF
Meetup Openshift Geneva 03/10
MagaliDavidCruz
 
PPTX
FICO Open Shift presentation
Nicholas Gerasimatos
 
PDF
Introduction to Red Hat OpenShift 4
HngNguyn748044
 
PDF
OpenShift Meetup - Summit 2021 (Part 1)
ConSol Consulting & Solutions Software GmbH
 
PDF
Perth MeetUp November 2023
Michael Price
 
PDF
Veer's Container Security
Jim Barlow
 
PDF
Kubernetes 101 - an Introduction to Containers, Kubernetes, and OpenShift
DevOps.com
 
PDF
Red Hat Container Strategy
Red Hat Events
 
PDF
Open shift deployment review getting ready for day 2 operations
Hendrik van Run
 
PPTX
Dev ops
Vikram Singh
 
PDF
OpenShift Meetup 8th july 2019 at ConSol - OpenShift v4
Robert Bohne
 
PDF
OpenShift – the open-source PaaS by Marek Jelen
Codemotion
 
PDF
OpenShift PaaS Overviewi by Marek Jelen 03-2013 CodeMotion Roma
OpenShift Origin
 
PDF
Build Your Own PaaS, Just like Red Hat's OpenShift from LinuxCon 2013 New Orl...
OpenShift Origin
 
PDF
Red hat's updates on the cloud & infrastructure strategy
Orgad Kimchi
 
PDF
Red Hat OpenShift Container Platform Overview
James Falkner
 
PDF
Red Hat OpenShift -- Innovation without limitation.pdf
ssuser1490e8
 
PDF
AWS Summit Singapore 2019 | Latest Trends for Cloud-Native Application Develo...
AWS Summits
 
PDF
Openshift 3.10 & Container solutions for Blockchain, IoT and Data Science
John Archer
 
PPTX
Red Hat Openshift Fundamentals.pptx
ssuser18b1c6
 
Meetup Openshift Geneva 03/10
MagaliDavidCruz
 
FICO Open Shift presentation
Nicholas Gerasimatos
 
Introduction to Red Hat OpenShift 4
HngNguyn748044
 
OpenShift Meetup - Summit 2021 (Part 1)
ConSol Consulting & Solutions Software GmbH
 
Perth MeetUp November 2023
Michael Price
 
Veer's Container Security
Jim Barlow
 
Kubernetes 101 - an Introduction to Containers, Kubernetes, and OpenShift
DevOps.com
 
Red Hat Container Strategy
Red Hat Events
 
Open shift deployment review getting ready for day 2 operations
Hendrik van Run
 
Dev ops
Vikram Singh
 
OpenShift Meetup 8th july 2019 at ConSol - OpenShift v4
Robert Bohne
 
OpenShift – the open-source PaaS by Marek Jelen
Codemotion
 
OpenShift PaaS Overviewi by Marek Jelen 03-2013 CodeMotion Roma
OpenShift Origin
 
Build Your Own PaaS, Just like Red Hat's OpenShift from LinuxCon 2013 New Orl...
OpenShift Origin
 
Red hat's updates on the cloud & infrastructure strategy
Orgad Kimchi
 
Red Hat OpenShift Container Platform Overview
James Falkner
 
Red Hat OpenShift -- Innovation without limitation.pdf
ssuser1490e8
 
AWS Summit Singapore 2019 | Latest Trends for Cloud-Native Application Develo...
AWS Summits
 
Openshift 3.10 & Container solutions for Blockchain, IoT and Data Science
John Archer
 
Red Hat Openshift Fundamentals.pptx
ssuser18b1c6
 
Ad

More from DevOps.com (20)

PPTX
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
DevOps.com
 
PPTX
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
DevOps.com
 
PDF
Next Generation Vulnerability Assessment Using Datadog and Snyk
DevOps.com
 
PPTX
Vulnerability Discovery in the Cloud
DevOps.com
 
PDF
2021 Open Source Governance: Top Ten Trends and Predictions
DevOps.com
 
PDF
A New Year’s Ransomware Resolution
DevOps.com
 
PPTX
Getting Started with Runtime Security on Azure Kubernetes Service (AKS)
DevOps.com
 
PDF
Don't Panic! Effective Incident Response
DevOps.com
 
PDF
Creating a Culture of Chaos: Chaos Engineering Is Not Just Tools, It's Culture
DevOps.com
 
PDF
Role Based Access Controls (RBAC) for SSH and Kubernetes Access with Teleport
DevOps.com
 
PDF
Monitoring Serverless Applications with Datadog
DevOps.com
 
PPTX
Securing medical apps in the age of covid final
DevOps.com
 
PDF
How to Build a Healthy On-Call Culture
DevOps.com
 
PPTX
The Evolving Role of the Developer in 2021
DevOps.com
 
PDF
Service Mesh: Two Big Words But Do You Need It?
DevOps.com
 
PPTX
Secure Data Sharing in OpenShift Environments
DevOps.com
 
PPTX
How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...
DevOps.com
 
PDF
Elevate Your Enterprise Python and R AI, ML Software Strategy with Anaconda T...
DevOps.com
 
PDF
Hotels, Hookups and Video Conferencing: A Top 10 Countdown to 2020's Worst Da...
DevOps.com
 
PDF
How IBM's Massive POWER9 UNIX Servers Benefit from InfluxDB and Grafana Techn...
DevOps.com
 
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
DevOps.com
 
Comparing Microsoft SQL Server 2019 Performance Across Various Kubernetes Pla...
DevOps.com
 
Next Generation Vulnerability Assessment Using Datadog and Snyk
DevOps.com
 
Vulnerability Discovery in the Cloud
DevOps.com
 
2021 Open Source Governance: Top Ten Trends and Predictions
DevOps.com
 
A New Year’s Ransomware Resolution
DevOps.com
 
Getting Started with Runtime Security on Azure Kubernetes Service (AKS)
DevOps.com
 
Don't Panic! Effective Incident Response
DevOps.com
 
Creating a Culture of Chaos: Chaos Engineering Is Not Just Tools, It's Culture
DevOps.com
 
Role Based Access Controls (RBAC) for SSH and Kubernetes Access with Teleport
DevOps.com
 
Monitoring Serverless Applications with Datadog
DevOps.com
 
Securing medical apps in the age of covid final
DevOps.com
 
How to Build a Healthy On-Call Culture
DevOps.com
 
The Evolving Role of the Developer in 2021
DevOps.com
 
Service Mesh: Two Big Words But Do You Need It?
DevOps.com
 
Secure Data Sharing in OpenShift Environments
DevOps.com
 
How to Govern Identities and Access in Cloud Infrastructure: AppsFlyer Case S...
DevOps.com
 
Elevate Your Enterprise Python and R AI, ML Software Strategy with Anaconda T...
DevOps.com
 
Hotels, Hookups and Video Conferencing: A Top 10 Countdown to 2020's Worst Da...
DevOps.com
 
How IBM's Massive POWER9 UNIX Servers Benefit from InfluxDB and Grafana Techn...
DevOps.com
 
Ad

Recently uploaded (20)

PDF
Jak MŚP w Europie Środkowo-Wschodniej odnajdują się w świecie AI
dominikamizerska1
 
PPTX
AUTOMATION AND ROBOTICS IN PHARMA INDUSTRY.pptx
sameeraaabegumm
 
PDF
SWEBOK Guide and Software Services Engineering Education
Hironori Washizaki
 
PDF
TrustArc Webinar - Data Privacy Trends 2025: Mid-Year Insights & Program Stra...
TrustArc
 
PDF
Why Orbit Edge Tech is a Top Next JS Development Company in 2025
mahendraalaska08
 
PPT
Interview paper part 3, It is based on Interview Prep
SoumyadeepGhosh39
 
PDF
Predicting the unpredictable: re-engineering recommendation algorithms for fr...
Speck&Tech
 
PDF
NewMind AI Journal - Weekly Chronicles - July'25 Week II
NewMind AI
 
PDF
Smart Trailers 2025 Update with History and Overview
Paul Menig
 
PDF
How Startups Are Growing Faster with App Developers in Australia.pdf
India App Developer
 
PDF
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
PDF
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
PDF
Chris Elwell Woburn, MA - Passionate About IT Innovation
Chris Elwell Woburn, MA
 
PDF
Complete JavaScript Notes: From Basics to Advanced Concepts.pdf
haydendavispro
 
PDF
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
PPTX
UiPath Academic Alliance Educator Panels: Session 2 - Business Analyst Content
DianaGray10
 
PDF
HubSpot Main Hub: A Unified Growth Platform
Jaswinder Singh
 
PPTX
Top iOS App Development Company in the USA for Innovative Apps
SynapseIndia
 
PDF
Impact of IEEE Computer Society in Advancing Emerging Technologies including ...
Hironori Washizaki
 
PDF
Presentation - Vibe Coding The Future of Tech
yanuarsinggih1
 
Jak MŚP w Europie Środkowo-Wschodniej odnajdują się w świecie AI
dominikamizerska1
 
AUTOMATION AND ROBOTICS IN PHARMA INDUSTRY.pptx
sameeraaabegumm
 
SWEBOK Guide and Software Services Engineering Education
Hironori Washizaki
 
TrustArc Webinar - Data Privacy Trends 2025: Mid-Year Insights & Program Stra...
TrustArc
 
Why Orbit Edge Tech is a Top Next JS Development Company in 2025
mahendraalaska08
 
Interview paper part 3, It is based on Interview Prep
SoumyadeepGhosh39
 
Predicting the unpredictable: re-engineering recommendation algorithms for fr...
Speck&Tech
 
NewMind AI Journal - Weekly Chronicles - July'25 Week II
NewMind AI
 
Smart Trailers 2025 Update with History and Overview
Paul Menig
 
How Startups Are Growing Faster with App Developers in Australia.pdf
India App Developer
 
Building Real-Time Digital Twins with IBM Maximo & ArcGIS Indoors
Safe Software
 
DevBcn - Building 10x Organizations Using Modern Productivity Metrics
Justin Reock
 
Chris Elwell Woburn, MA - Passionate About IT Innovation
Chris Elwell Woburn, MA
 
Complete JavaScript Notes: From Basics to Advanced Concepts.pdf
haydendavispro
 
Transcript: New from BookNet Canada for 2025: BNC BiblioShare - Tech Forum 2025
BookNet Canada
 
UiPath Academic Alliance Educator Panels: Session 2 - Business Analyst Content
DianaGray10
 
HubSpot Main Hub: A Unified Growth Platform
Jaswinder Singh
 
Top iOS App Development Company in the USA for Innovative Apps
SynapseIndia
 
Impact of IEEE Computer Society in Advancing Emerging Technologies including ...
Hironori Washizaki
 
Presentation - Vibe Coding The Future of Tech
yanuarsinggih1
 

Securing Red Hat OpenShift Containerized Applications At Enterprise Scale

  • 1. Red Hat/CyberArk webinar Jody Hunt Director, DevOps Security CyberArk Vijay Arungurikai Senior Solutions Architect Embedded & ISV Partners, Red Hat
  • 2. F16625-200131 The world’s leading provider of open source enterprise IT solutions 2 *Red Hat client data and Fortune 500 list, October 2019. Note: Currency in U.S. dollars. MORE THAN 90%of the FORTUNE 500 RED HAT use PRODUCTS & SOLUTIONS* ~13,815 EMPLOYEES 105+ OFFICES 40+ COUNTRIES THE FIRST $3 OPEN SOURCE COMPANY IN THE WORLD BILLION
  • 3. From communities to enterprise 3
  • 4. 44 Red Hat Enterprise Linux Red Hat Virtualization Red Hat OpenStack Platform Red Hat Ceph Storage Infrastructure Software Container Platform Red Hat OpenShift Container Platform Developer Tools Automation & Management Red Hat Ansible Automation Platform Red Hat Satellite Red Hat Insights Red Hat CloudForms Middleware & Integration Red Hat Fuse Red Hat Decision Manager Red Hat Process Automation Manager Application & Business processes Red Hat JBoss EAP Red Hat AMQ Red Hat 3Scale API Mgmt Red Hat OpenShift Application Runtimes Red Hat CodeReady Workspace Services Red Hat Learning Subscription Red Hat Certification Red Hat Consulting Red Hat OPEN Innovation Labs Product Portfolio
  • 5. NEW INSTALLER PLATFORMS STORAGE AUTOMATION CLOUD-NATIVE DEV TOOLS RHV IPI Azure & OpenStack UPI DNS forwarding Kubernetes 1.17 OpenShift Serverless is GA Helm 3 support is GA OpenShift Pipelines is TP Developer Console gains monitoring & Helm features CSI topology support CSI Volume snapshot, restore, clone (Tech Preview) iSCSI PVs for internal registry Auto image pruning in registry OpenShift 4.4 5
  • 6. 6 Developer Productivity Cluster Services Automated Ops ⠇Over-The-Air Updates ⠇Monitoring ⠇Registry ⠇Networking ⠇Router ⠇KubeVirt ⠇OLM ⠇Helm Kubernetes Developer CLI ⠇VS Code extensions ⠇IDE Plugins Code Ready Workspaces CodeReady Containers Service Mesh ⠇Serverless Builds ⠇CI/CD Pipelines Full Stack Logging Chargeback Databases ⠇Languages Runtimes ⠇Integration Business Automation 100+ ISV Services Platform Services Application Services Developer Services Physical Virtual Private cloud Public cloud OpenShift Kubernetes Engine Build Cloud-Native AppsManage Workloads Multi-cluster Management Discovery ⠇Policy ⠇Compliance ⠇Configuration ⠇Workloads Advanced Cluster Management OpenShift Container Platform Managed cloud (Azure, AWS, IBM, Red Hat) Red Hat Enterprise Linux & RHEL CoreOS OpenShift Container Platform
  • 7. Automated operations A consistent container application platform Multi-tenant Network traffic control Over-the-air updates Bare metal, VMware vSphere, Red Hat Virtualization, Red Hat OpenStack Platform, Amazon Web Services, Microsoft Azure, Google, IBM Cloud Pluggable architecture Monitoring & chargeback Secure by default FROM YOUR DATACENTER TO THE CLOUD 7
  • 8. OpenShift enables developer productivity SPRING & JAVA™ EE MICROSERVICES FUNCTIONS LANGUAGES DATABASES APPLICATION SERVICES LINUX WINDOWS* * coming soon CODE BUILD TEST DEPLOY MONITORREVIEW Self-service provisioning Automated build & deploy CI/CD pipelines Consistent environments Configuration management App logs & metrics 8
  • 9. Full Stack Automation (IPI) Pre-existing Infrastructure (UPI) Bare Metal 4.4 Supported Providers IBM Power Systems * * Note: Planned for an upcoming 4.3.z release on April 30th * Denotes new addition in OCP 4.4 9
  • 10. OpenShift offers the broadest set of hybrid cloud services Red Hat OpenShift Dedicated Managed By Red Hat or Customer Managed or Customer Managed Red Hat OpenShift Dedicated Managed By Red Hat or Customer Managed Red Hat OpenShift on IBM Cloud or Customer Managed (UPI) Customer Managed On-premises Azure Red Hat OpenShift Jointly Managed & Supported Jointly Engineered 10
  • 11. 11 Red Hat OpenShift has seen 70%+ market expansion Red Hat OpenShift customers ● Supported on every major cloud: AWS, Azure, GCP, IBM, AliCloud ● Broadest hybrid cloud market adoption ● 100s of ISVs supporting operators ● Expanded AI/ML focus ● 1st to market with service mesh ● 1st to market with serverless ● New CodeReady developer experience ● New security, encryption enhancements ● Integrated IBM Portfolio via CloudPaks ● ...and much more 1700+ FY 2015 FY 2016 FY 2017 FY 2018 FY 2019 FY 2020 500 0 1000 1500 2000
  • 12. 12 A broad ecosystem of workloads Operator-backed services allow for a SaaS experience on your own infrastructure Relational DBs NoSQL DBs Storage Messaging Security Monitoring AI/ML Big Data DevOps
  • 13. Operator SDK 13 Enabling everybody to write Operators Support for Helm 3 Build Operators from Helm v2 and v3 charts Ansible collections Ansible Operator supports k8s module collection Custom metrics Every Operator supports custom metric endpoints Generate Packaging Operator Metadata (CSV) for OLM gets generated Kubernetes Compatibility Keep in sync with new Kubernetes releases Scorecard v2 Enable testing your Operator in a pipeline
  • 14. Do your applications use privileged credentials? Secrets management for Red Hat OCP Jody Hunt, DevOps SME 14
  • 15. EVERYBODY WANTS A SECURE DEVOPS FLOW, BUT…
  • 16. SHIFTING SECURITY LEFT INTO DEVELOPMENT WORKFLOWS 16 Developers DevOps Security Empower Security Team • Highlight the app & tool risk • Leverage single platform – human/non-human solution serves all • Security focus • Manage security budget Enable Developer/DevOps • Easy to use (consume secrets) • Prebuilt integrations • Open source and Secretless Free developers from security burden • Compliance, audit requests, human creds • Security budget Plan Code Create Test Release Deploy Operate
  • 17. THE PROBLEM WE’RE SOLVING There are lots of places to store secrets. But: • Platform solutions only work for those platforms • Tool solutions lack security • Most not enterprise ready • Hard to share best-practices • SoD not enforced • GRC reporting is impossible Islands of Security Hiera DatabagsVault IAM / KMS IAM / KMS Home Grown Solutions SecretsSecrets IAM / KMS
  • 18. THE VISION WE’RE DELIVERING ON Enterprise-Spanning Service delivered by IT Security IaaSOn-Prem Infrastructure and Apps (*NIX, Windows, zOS) DevOps ToolsPaaS Security Solutions IT Mgt Software App Servers and Custom Apps RPA PAS Consistently enforce privilege security policies for both human users and non-human identities
  • 19. CENTRAL AUDIT, SECURITY POLICY, SECRETS ROTATION Application Access Manager Consistent, Unified Enterprise-Wide Privileged Access Security Program CyberArk Vault Multi-Persona UI Security Admin Developer /DevOps Admin Threat Detection and Analytics Credential Providers – Static Apps Agent-based Credential Rotation /Policy Driven Monitoring and Audit Secrets Management – Dynamic Agentless
  • 20. Dynamic Access Provider (Conjur Open Source) OCP4 Lab Architecture Linux Host (Azure) Windows Hosts (my Mac) CyberArk Enterprise Password Vault Synchronizer OCP4 Cluster (AWS) User Namespaces Lab App Authen -ticator cybrlab Namespace ServiceService
  • 21. SECRETS ACCESS WORKFLOW Authenticate Access Token Requestor Application Access Manager Dynamic Access Provider Targe t Access per Policy Retrieve secrets Use secrets Access Token expires after 8 mins Audited activity
  • 22. • Lab 1: • Authenticator runs as a Sidecar • App pulls DB creds with REST API • App connects to DB • Lab 2: Secrets Injection • Leverages Summon component • Authenticator runs as an Init container • Summon pulls DB creds & calls app w/ creds in env vars • App connects to DB • Lab 3: K8s Secrets • Authenticator runs as an Init Container • K8s secret manifest names DB cred names • Authenticator retrieves DB creds & dynamically patches K8s secret w/ DB cred values • App connects to DB • Lab 4: Secretless Broker • Authenticator runs as a Sidecar Container listening on DB port • App attempts to connect to DB on local port • Authenticator retrieves DB creds, connects to DB, proxies connection for app • App connects to DB CYBERARK OCP4 LABS
  • 23. THE SECRETS LIFECYCLE TODAY Secrets Storage Secrets Delivery Application s
  • 24. • Monthly DevOps Workshops (Virtual) • “CyberArk DevOps Workshop” • July 16th , 1pm Eastern • https://www.cyberark.com/devops-workshops • CyberArk Red Hat Integrations • www.cyberark.com/redhat • RedHat Ecosystem for CyberArk • access.redhat.com/containers/#/vendor/cyberark • CyberArk AAM documentation • docs.cyberark.com • lower right is Dynamic Access Provider • Conjur Open Source Resources • Open Source Secrets Management conjur.org • Blog conjur.org/blog • Developer Community cyberarkcommons.org • Secretless Broker: conjur.org/Secretless • Enterprise Resources • Application Access Manager • DevOps Security EXPLORE SECRETS MANAGEMENT AND DEVOPS SECURITY : 24
  • 25. linkedin.com/company/red-hat youtube.com/user/RedHatVideos facebook.com/redhatinc twitter.com/RedHat Red Hat is the world’s leading provider of enterprise open source software solutions. Award-winning support, training, and consulting services make Red Hat a trusted adviser to the Fortune 500. Thank you