●
●
●
●
●
3
●
●
●
●
●
4
5
6
●
●
●
●
●
●
7
●
●
●
●
●
●
INFRASTRUCTURE APPLICATIONS
OpenShift Application Lifecycle Management
(CI/CD)
Build Automation Deployment Automation
Service Catalog
(Language Runtimes, Middleware, Databases)
Self-Service
Networking Storage
Logs &
Metrics
Security
Container Orchestration & Cluster Management
(Kubernetes)
Enterprise Container Host
CONTROL
DEFEND
EXTEND
8
9
●
●
10
11
●
SELinux
Kernel & User
namespaces
Cgroups SeccompCapabilities
12
●
●
●
●
●
13
●
●
●
https://thenewstack.io/kubernetes-deployments-work/
14
●
●
●
●
Container Runtime Daemon e.g. crio
Container Runtime Interface CRI-O
Kubernetes Kublet
Linux Container
}OCI Compliance
Container Runtime e.g. runC
15
●
●
●
16
●
●
●
●
17
Events:
Cloud,
Host,
Container,
Application
Event and Log aggregation
Normalize and store
Visualize and Alert
18
●
●
●
●
●
SKOPEO
Image
Repository
Image
Registry
Host
/var/lib/containers
/var/lib/docker
19
UNIT
TEST
CODE
QUAL
VULN
SCAN
INT
TEST
QA
UAT
-Cucumber
-Arquillian
-Junit
-Sonarqube
-Fortify
-AtomicScan
-AquaSecurity
-Black Duck
-Twistlock
●
●
●
●
●
☒
☑
20
●
●
●
21
●
●
●
●
22
●
●
●
●
●
OpenShift Application Lifecycle Management
(CI/CD)
Build Automation Deployment Automation
Service Catalog
(Language Runtimes, Middleware, Databases)
Self-Service
Networking Storage
Logs &
Metrics
Security
Container Orchestration & Cluster Management
(Kubernetes)
Enterprise Container Host
23
Cloud-Native: A New Ecosystem for Putting Containers into Production

Cloud-Native: A New Ecosystem for Putting Containers into Production