Operational characteristic-based container management
In some embodiments, operational characteristics-based container management may include receiving, by a device and from a container agent executing in a container environment, operational characteristics of an application instance executing in the container environment; determining, by the device and based on the operational characteristics, whether the application instance executing in the container environment is associated with a policy violation for application instances; generating, by the device, a notification of the policy violation when the device determines that the application instance is associated with the policy violation; and causing, by the device, the container environment to perform a mitigation action of the policy violation by the application instance.
1 . A method, comprising:
receiving, by a device and from a container agent executing in a container environment, operational characteristics of an application instance executing in the container environment, the operational characteristics comprising metrics indicative of a maintenance recency for the application instance;
determining, by the device and based on the operational characteristics, whether the application instance executing in the container environment is associated with a policy violation for application instances by comparing the metrics indicative of maintenance recency to a security status recency threshold in a policy for the application instance, the security status recency threshold specifying a recency of one or more of patching, updating, or administrative activity, wherein the policy is configured based on statistical analysis of operational characteristics of the application instances, and wherein determining includes identifying the application instance as an orphaned instance based on the comparison;
generating, by the device, a notification of the policy violation when the device determines that the application instance is associated with the policy violation; and
causing, by the device, the container environment to perform a mitigation action of the policy violation by the application instance.
2 . The method as in claim 1 , wherein the operational characteristics comprise computational resource usage metrics for the application instance executing in the container environment.
3 . The method as in claim 1 , wherein the operational characteristics comprise an indication of a security status of the application instance.
4 . The method as in claim 1 , wherein the metrics indicative of maintenance recency include a metric indicative of a recency of one or more of an administrative activity for the application instance, a software update to the application instance, or a security patch applied to the application instance.
5 . The method of claim 1 , wherein the operational characteristics comprise an indication of a criticality of monitored network traffic of the application instance.
6 . The method as in claim 5 , further comprising determining that the application instance executing in the container environment is associated with the policy violation when the indication of the criticality of the monitored network traffic of the application instance indicates that the monitored network traffic of the application instance is non-critical.
7 . The method as in claim 1 , further comprising:
assigning an expiration date to the application instance executing in the container environment; and
flagging the application instance executing in the container environment for a policy violation review of the operational characteristics upon the expiration date.
8 . The method as in claim 1 , wherein the mitigation action comprises blocking of non-critical network traffic at the application instance executing in the container environment.
9 . The method as in claim 1 , wherein the mitigation action comprises reallocating computing resources of the container environment from the application instance.
10 . The method as in claim 1 , wherein generating the notification of the policy violation comprises providing the notification to a dashboard for managing application instances.
11 . The method of claim 1 , wherein the operational characteristics further comprise metrics indicative of a business purpose classification of monitored network traffic associated with the application instance, wherein determining includes identifying whether the application instance executing in the container environment is associated with the policy violation based on whether the business purpose classification is related to a targeted business purpose for the application instance.
12 . An apparatus, comprising:
one or more network interfaces;
a processor coupled to the one or more network interfaces and configured to execute one or more processes; and
a memory configured to store a process that is executable by the processor, the process when executed configured to:
receive, from a container agent executing in a container environment, operational characteristics of an application instance executing in the container environment, the operational characteristics comprising metrics indicative of a maintenance recency for the application instance;
determine, based on the operational characteristics, whether the application instance executing in the container environment is associated with a policy violation for application instances by comparing the metrics indicative of maintenance recency to a security status recency threshold in a policy for the application instance, the security status recency threshold specifying a recency of one or more of patching, updating, or administrative activity, wherein the policy is configured based on statistical analysis of operational characteristics of the application instances, and wherein to determine includes to identify the application instance as an orphaned instance based on the comparison;
generate a notification of the policy violation when the application instance is associated with the policy violation; and
cause the container environment to perform a mitigation action of the policy violation by the application instance.
13 . The apparatus of claim 12 , wherein the operational characteristics comprise computational resource usage metrics for the application instance executing in the container environment.
14 . The apparatus of claim 12 , wherein the operational characteristics comprise an indication of a security status of the application instance.
15 . The apparatus of claim 12 , wherein the metrics indicative of maintenance recency include a metric indicative of a recency of one or more of an administrative activity for the application instance, a software update to the application instance, or a security patch applied to the application instance.
16 . The apparatus of claim 12 , wherein the operational characteristics comprise an indication of a criticality of monitored network traffic of the application instance.
17 . The apparatus of claim 16 , further comprising determining that the application instance executing in the container environment is associated with the policy violation when the indication of the criticality of the monitored network traffic of the application instance indicates that the monitored network traffic of the application instance is non-critical.
18 . The apparatus of claim 12 , the process when executed further configured to:
assign an expiration date to the application instance executing in the container environment; and
flag the application instance executing in the container environment for a policy violation review of the operational characteristics upon the expiration date.
19 . The apparatus of claim 12 , wherein the mitigation action comprises blocking of non-critical network traffic at the application instance executing in the container environment.
20 . A tangible, non-transitory, computer-readable medium storing program instructions that cause a device to execute a process comprising:
receiving, by the device and from a container agent executing in a container environment, operational characteristics of an application instance executing in the container environment, the operational characteristics comprising metrics indicative of a maintenance recency for the application instance;
determining, by the device and based on the operational characteristics, whether the application instance executing in the container environment is associated with a policy violation for application instances by comparing the metrics indicative of maintenance recency to a security status recency threshold in a policy for the application instance, the security status recency threshold specifying a recency of one or more of patching, updating, or administrative activity, wherein the policy is configured based on statistical analysis of operational characteristics of the application instances, and wherein determining includes identifying the application instance as an orphaned instance based on the comparison;
generating, by the device, a notification of the policy violation when the device determines that the application instance is associated with the policy violation; and
causing, by the device, the container environment to perform a mitigation action of the policy violation by the application instance.