Connect Kubernetes and Amazon ECS clusters, deploy Container Protection policies and proxy settings, create and manage Kubernetes cluster groups, and monitor your container environment from Inventory.
Different options are available for Kubernetes and Amazon ECS clusters. The options
are
outlined in the tables below.
Tip
|
Inventory overview
Select Kubernetes or Amazon ECS to view a complete overview of all of your connected
clusters.
Each security finding type displays a 24-hour trend that compares the current count
to the
count from the previous 24-hour period, so you can see whether findings are increasing,
decreasing, or unchanged.
The overview scopes to whatever you select in the cluster tree. Select the whole environment,
a cloud provider, a group, or a cluster to see aggregated counts and findings across
all
resources in that scope. Select an individual resource, like a node or pod for Kubernetes,
or a
service or task for Amazon ECS, to narrow the inventory count and security findings
to that
resource.
NoteDeployment findings are reported at the cluster level only.
|
Kubernetes
Inventory overview provides a complete picture of your cluster status,
including the number of nodes, pods, containers, and images in your environment. You
can also
view the details for all of your Kubernetes clusters, as well as search and apply
filters to
query your cluster resources using specific criteria. For example, you could apply
filters to
show only the clusters with an unhealthy status.
In Findings overview, view a quick summary of all your policy
violations or click Show more for more details. You can see a summary for
deployment, continuous, Runtime Security, Runtime findings for vulnerabilities, malware,
and
secrets, file integrity monitoring, and compliance. Click the security finding number
to see
more details about the findings on the Log page.
Amazon ECS
Inventory overview provides a complete picture of your cluster status,
including the number of services, tasks, containers, and images in your environment.
You can
also view the details for all of your Amazon ECS clusters, as well as search and apply
filters
to query your cluster resources using specific criteria. For example, you could apply
filters to
show only the clusters with an unhealthy status.
In Findings overview, view a quick summary of all your policy
violations or click Show more for more details about deployment, Runtime
Security, file integrity monitoring, and Runtime Vulnerabilities. Click the security
finding
number to see more details about the findings on the Log page.
Kubernetes
The following table outlines the options available for Kubernetes clusters.
|
Option
|
Description
|
||||
|
View details about your container environment
|
Select an orchestration platform within Kubernetes to view the inventory overview
for the
clusters in that platform.
The following orchestrations platforms are available:
|
||||
|
Add new Kubernetes clusters
|
Select an orchestration platform from the tree. Click Add Cluster
(if clusters have previously been added to the orchestration platform) or Deploy
protection to a Kubernetes Cluster (if no clusters have previously been added
to the orchestration platform).
For detailed instructions, see:
|
||||
|
Stop protecting Kubernetes clusters
|
Select Kubernetes or an orchestration platform from the tree,
select the radio button next to the cluster name, and then click Remove
Cluster.
|
||||
|
Create and manage cluster groups
|
Organize Kubernetes clusters into groups for enhanced control and streamlined
management.
|
||||
|
Change cluster settings
|
Select a cluster from the tree to manage settings. You can change the following
settings.
|
||||
|
Set cluster protection status by version gap
|
This setting changes the cluster protections status to "unhealthy" when a current
deployed version falls behind the latest release or minor version update by a predefined
version gap.
To enable this setting and set a version gap for clusters, select a Kubernetes cluster,
then click on the gear icon on the top right of the screen.
|
Amazon ECS
The following table outlines the options available for Amazon ECS cluster.
|
Option
|
Options
|
|
View details about your container environment
|
Container Security provides a tree view to manage the protection of all your connected
Amazon ECS clusters.
|
|
Add new Amazon ECS clusters
|
Select Amazon ECS, a cloud account, or a region from the tree.
Click Add account (if other clusters have previously been added) or
Add and protect Amazon ECS assets (if no clusters have previously
been added).
For detailed instructions, see:
|
|
Enable or disable runtime security and scanning on clusters
|
Select one or more clusters from the tree, then click Edit in
Cluster details to enable or disable Runtime Security or Runtime Vulnerability
Scanning.
|
|
Assign new policies
|
Select a cluster from the tree and click Edit in Cluster details.
In the Policy field, select from existing Container Security
policies or click Manage policies to modify the current policy
settings.
|
|
Set cluster protection status by version gap
|
This setting changes the cluster protections status to "unhealthy" when a current
deployed version falls behind the latest release or minor version update by a predefined
version gap.
To enable this setting and set a version gap for clusters, select a cluster, then
click on the gear icon on the top right of the screen.
|
