Copyright © SUSE 2022
NeuVector
Coffee Break #1
Copyright © SUSE 2022
Coffee Break NeuVector #1
✓ Présentation et Architecture
✓ Installation
✓ Premiers pas
Copyright © SUSE 2022
Copyright © SUSE 2022
Présentation et
Architecture
Copyright © SUSE 2022 4
SUSE’s Enterprise Container Management Stack
Authentication Policy Enforcement & Governance
Simplified Cluster Operations & Infrastructure Management (Run & Manage)
Platform Services (Build & Secure)
Amazon
EKS
Azure
AKS
Google
GKE
Cloud
Datacenter Edge
Branch
Dev
K8s Version
Management
GitOps Continuous
Delivery
Cluster Templates &
Config Enforcement
Node Pool
Management
Cluster Provisioning &
Lifecycle Management
Centralized Audit &
CIS Benchmarking
AIOps, Monitoring &
Logging
OPA & KubeWarden
RBAC, Pod &
Network Policies
Rancher
Catalog
Monitoring &
Alerts
Dashboards &
Observability
Service
Mesh
Longhorn
Storage
Cloud-Native Hyperconverged Infrastructure
Virtual Machine &
OS* Management
Container
Security
Enterprise
Linux
Developer
Services
Deployment
Engine
Container
Image
Rancher
Desktop
SUSE Linux
Enterprise*
Ubuntu
Linux
Oracle
Linux
Amazon
Linux
Red Hat
Linux
Copyright © SUSE 2022
Layered Security : Defense in depth
Supply Chain Security
Vulnerability Scanning
Compliance Scanning
Admission Control
Runtime Security
Runtime Scanning
Threat Based Controls
Zero-Trust Controls
Copyright © SUSE 2022
Supply Chain Security
DEVELOPER
Commits
Code
PRIV/PUB
REGISTRY
Admission
Control
RUN-TIME
Supply Chain Security
Vulnerability Scanning
Compliance Scanning
Admission Control
CI/CD
PIPELINE
Pass
Build
Copyright © SUSE 2022
Run Time Security: Defense in Depth
CVEs
Data Loss Prevention (DLP)
Network Attacks
Web App Firewall (WAF)
Admission Control
Threat Based
Controls
Automated Learning
Network
Process
File Access
Security as Code
Zero-Trust
Controls
Runtime Security
Runtime Scanning
Threat Based Controls
Zero-Trust Controls
Copyright © SUSE 2022
Pod Pod Pod
Node Node Node
Pod
Node
Pod
Node
Virtual Switch Virtual Switch Virtual Switch Virtual Switch Virtual Switch
Pod Pod Pod Pod
Pod Pod Pod Pod Pod
Controller Controller Controller
Manage Policies
REST API
Scanner Scanner
Parallel scanning
FAST
Scales for largerepositories
Web UI
Manager User Interface
CLI Console
Enforcer Enforcer Enforcer Enforcer Enforcer
Enforce Security Policies
Inspect Network Traffic
Deploy as Daemonset
Architecture NeuVector
Copyright © SUSE 2022
Installation
Copyright © SUSE 2022
Install NeuVector from Catalog
Copyright © SUSE 2022
Configure Chart (1/4)
RKE : use Docker Runtime option
RKE2/k3s : use k3s Containerd Runtime option
Copyright © SUSE 2022
Configure Chart (2/4)
Configure persistent storage
Copyright © SUSE 2022
Configure Chart (3/4)
Copyright © SUSE 2022
Configure Chart (4/4)
Copyright © SUSE 2022
Login
Copyright © SUSE 2022
Premiers pas
Copyright © SUSE 2022
Coffee Break NeuVector #2
✓ Scanning & Compliance
✓ Admission Control
✓ Network Attacks
Coffee Break NeuVector #3
✓ Zero-Trust
✓ Web Application Firewall (WAF)
✓ Data Loss Prevention (DLP)
Copyright © SUSE 2022
Rejoignez la
communauté
https://community.suse.com

Coffee Break NeuVector

  • 1.
    Copyright © SUSE2022 NeuVector Coffee Break #1
  • 2.
    Copyright © SUSE2022 Coffee Break NeuVector #1 ✓ Présentation et Architecture ✓ Installation ✓ Premiers pas
  • 3.
    Copyright © SUSE2022 Copyright © SUSE 2022 Présentation et Architecture
  • 4.
    Copyright © SUSE2022 4 SUSE’s Enterprise Container Management Stack Authentication Policy Enforcement & Governance Simplified Cluster Operations & Infrastructure Management (Run & Manage) Platform Services (Build & Secure) Amazon EKS Azure AKS Google GKE Cloud Datacenter Edge Branch Dev K8s Version Management GitOps Continuous Delivery Cluster Templates & Config Enforcement Node Pool Management Cluster Provisioning & Lifecycle Management Centralized Audit & CIS Benchmarking AIOps, Monitoring & Logging OPA & KubeWarden RBAC, Pod & Network Policies Rancher Catalog Monitoring & Alerts Dashboards & Observability Service Mesh Longhorn Storage Cloud-Native Hyperconverged Infrastructure Virtual Machine & OS* Management Container Security Enterprise Linux Developer Services Deployment Engine Container Image Rancher Desktop SUSE Linux Enterprise* Ubuntu Linux Oracle Linux Amazon Linux Red Hat Linux
  • 5.
    Copyright © SUSE2022 Layered Security : Defense in depth Supply Chain Security Vulnerability Scanning Compliance Scanning Admission Control Runtime Security Runtime Scanning Threat Based Controls Zero-Trust Controls
  • 6.
    Copyright © SUSE2022 Supply Chain Security DEVELOPER Commits Code PRIV/PUB REGISTRY Admission Control RUN-TIME Supply Chain Security Vulnerability Scanning Compliance Scanning Admission Control CI/CD PIPELINE Pass Build
  • 7.
    Copyright © SUSE2022 Run Time Security: Defense in Depth CVEs Data Loss Prevention (DLP) Network Attacks Web App Firewall (WAF) Admission Control Threat Based Controls Automated Learning Network Process File Access Security as Code Zero-Trust Controls Runtime Security Runtime Scanning Threat Based Controls Zero-Trust Controls
  • 8.
    Copyright © SUSE2022 Pod Pod Pod Node Node Node Pod Node Pod Node Virtual Switch Virtual Switch Virtual Switch Virtual Switch Virtual Switch Pod Pod Pod Pod Pod Pod Pod Pod Pod Controller Controller Controller Manage Policies REST API Scanner Scanner Parallel scanning FAST Scales for largerepositories Web UI Manager User Interface CLI Console Enforcer Enforcer Enforcer Enforcer Enforcer Enforce Security Policies Inspect Network Traffic Deploy as Daemonset Architecture NeuVector
  • 9.
    Copyright © SUSE2022 Installation
  • 10.
    Copyright © SUSE2022 Install NeuVector from Catalog
  • 11.
    Copyright © SUSE2022 Configure Chart (1/4) RKE : use Docker Runtime option RKE2/k3s : use k3s Containerd Runtime option
  • 12.
    Copyright © SUSE2022 Configure Chart (2/4) Configure persistent storage
  • 13.
    Copyright © SUSE2022 Configure Chart (3/4)
  • 14.
    Copyright © SUSE2022 Configure Chart (4/4)
  • 15.
  • 16.
    Copyright © SUSE2022 Premiers pas
  • 17.
    Copyright © SUSE2022 Coffee Break NeuVector #2 ✓ Scanning & Compliance ✓ Admission Control ✓ Network Attacks Coffee Break NeuVector #3 ✓ Zero-Trust ✓ Web Application Firewall (WAF) ✓ Data Loss Prevention (DLP)
  • 18.
    Copyright © SUSE2022 Rejoignez la communauté https://community.suse.com