Scalable Runtime Integrity Protection for Helm Based Applications on Kubernetes Cluster


연구 분야: Software Development



학회: 2021 IEEE International Conference on Big Data (Big Data)


초록

Enterprises adopting cloud increasingly use container orchestration systems (e.g., Kubernetes) to manage applications and their configurations at scale. In Kubernetes environment, developers use package managers (e.g., Helm) for bundling, distributing, and deploying applications. These developments in cloud native applications have introduced new challenges. One of the challenges is protecting the integrity of application packages (e.g., Helm chart) deployed in a large-scale enterprise cluster. Existing tools for verifying integrity of Helm charts are limited to verify provenance and integrity of application packages. Therefore, in this work, we propose a mechanism to verify provenance and integrity of Helm charts at the cluster-side by addressing the granularity gap to verify each resource in a chart. We demonstrate how our approach successfully enforces integrity of Helm charts and evaluate the cost of integrity enforcement with a preliminary study.


Author Profile
Kugamoorthy Gajananan

IBM Research - Tokyo IBM Japan Tokyo Japan

Japan
Author Profile
Hirokuni Kitahara

IBM Research - Tokyo IBM Japan Tokyo Japan

Japan
Author Profile
Ruriko Kudo

IBM Research - Tokyo IBM Japan Tokyo Japan

Japan

📄 논문 정보

발행 연도 2021년
인용수 2
출판 국가 Japan
사이트 IEEE
좋아요 수 0

연관 논문 목록 (140건)