Kubernetes Security and Observability by Alex Pollitt & Manish Sampat
Author:Alex Pollitt & Manish Sampat [Alex Pollitt]
Language: eng
Format: epub
Publisher: O'Reilly Media, Inc.
Published: 2021-11-01T16:00:00+00:00
Figure 5-2. Components of an observability tool for Kubernetes
Figure 5-2 shows that you need the following components for your observability implementation:
Telemetry Collection
As mentioned, your observability solution needs to collect telemetry data from various sensors in your cluster. It needs to be distributed and Kubernetes-native. It must support sensors across all layers, from L3 to L7. It also needs to collect information about Kubernetes infrastructure (e.g., DNS and API server logs) and Kubernetes activity (these are known as audit logs). As described before, this information must be collected in the context of deployments and services.
Analytics and Visibility
In this layer, the system must provide visualizations that are specific to Kubernetes operations (e.g., service graph, Kubernetes platform view, application views). We will cover some common visualizations that are native to Kubernetes. We recommend you pick a solution that leverages machine learning techniques for baselining and reporting anomalies. Finally, the system needs to support the ability for operators to enable pod-to-pod packet capture (note that this is not the same as enabling packet capture on the host interface, as the pod-level visibility is lost). We will cover this in the next section.
Security and Troubleshooting Applications
The observability system you implement must support distributed tracing as described in the previous section to help troubleshoot applications. We also recommend the use of advanced machine learning techniques to understand Kubernetes cluster behavior and predict performance or security concerns. Please note that this is a new area and there is ongoing innovation in it.
Download
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Sass and Compass in Action by Wynn Netherland Nathan Weizenbaum Chris Eppstein Brandon Mathis(7799)
Grails in Action by Glen Smith Peter Ledbrook(7712)
Azure Containers Explained by Wesley Haakman & Richard Hooper(6737)
Configuring Windows Server Hybrid Advanced Services Exam Ref AZ-801 by Chris Gill(6735)
Running Windows Containers on AWS by Marcio Morales(6249)
Kotlin in Action by Dmitry Jemerov(5080)
Microsoft 365 Identity and Services Exam Guide MS-100 by Aaron Guilmette(5003)
Combating Crime on the Dark Web by Nearchos Nearchou(4589)
Microsoft Cybersecurity Architect Exam Ref SC-100 by Dwayne Natwick(4512)
Management Strategies for the Cloud Revolution: How Cloud Computing Is Transforming Business and Why You Can't Afford to Be Left Behind by Charles Babcock(4431)
The Ruby Workshop by Akshat Paul Peter Philips Dániel Szabó and Cheyne Wallace(4266)
The Age of Surveillance Capitalism by Shoshana Zuboff(3968)
Python for Security and Networking - Third Edition by José Manuel Ortega(3833)
Learn Windows PowerShell in a Month of Lunches by Don Jones(3521)
The Ultimate Docker Container Book by Schenker Gabriel N.;(3501)
Learn Wireshark by Lisa Bock(3423)
Mastering Python for Networking and Security by José Manuel Ortega(3368)
Mastering Azure Security by Mustafa Toroman and Tom Janetscheck(3342)
Blockchain Basics by Daniel Drescher(3314)
