Techniques for contextually applying a security policy on a software container
A system and method for applying a cybersecurity contextual policy in a computing environment are disclosed. In an embodiment, the method includes: detecting a cybersecurity object on a virtualization, the virtualization deployed in a computing environment; detecting a policy of the computing environment, the policy including a conditional rule; generating a contextual policy based on: the conditional rule, and an exception to the conditional rule based on the cybersecurity object; and configuring an admission controller of a software container cluster deployed in the computing environment to apply the contextual policy.
1 . A method for applying a cybersecurity contextual policy in a computing environment, comprising:
detecting a cybersecurity object on a virtualization, the virtualization deployed in a computing environment;
detecting a policy of the computing environment, the policy including a conditional rule;
generating a contextual policy based on: the conditional rule, and an exception to the conditional rule based on the cybersecurity object; and
configuring an admission controller of a software container cluster deployed in the computing environment to apply the contextual policy.
2 . The method of claim 1 , further comprising:
configuring the admission controller to apply the contextual policy on a plurality of software containers deployed in the software container cluster.
3 . The method of claim 1 , further comprising:
applying the policy to a code object, wherein the code object is utilized to deploy the virtualization.
4 . The method of claim 1 , wherein the conditional rule is any one of: an exclusionary rule, or an inclusionary rule.
5 . The method of claim 1 , further comprising:
detecting a virtualization deployed in the computing environment which is an exception to the conditional rule; and
generating the exception based on a parameter of the detected virtualization.
6 . The method of claim 1 , further comprising:
intercepting a request from a software container to an application programming interface (API); and
applying the contextual policy to the request.
7 . The method of claim 6 , further comprising:
configuring a webhook in the software container cluster to intercept requests from a container of a first node; and
configuring the webhook to send the intercepted requests to the admission controller.
8 . The method of claim 1 , further comprising:
configuring a second admission controller of a second software container cluster deployed in a second computing environment to apply the contextual policy, wherein the second computing environment is deployed on a cloud computing infrastructure which is different than a cloud computing infrastructure on which the cloud computing environment is deployed.
9 . The method of claim 1 , wherein the admission controller is any one of: a validating admission controller, a mutating admission controller, and a combination thereof.
10 . A non-transitory computer-readable medium storing a set of instructions for applying a cybersecurity contextual policy in a computing environment, the set of instructions comprising:
one or more instructions that, when executed by one or more processors of a device, cause the device to:
detect a cybersecurity object on a virtualization, the virtualization deployed in a computing environment;
detect a policy of the computing environment, the policy including a conditional rule;
generate a contextual policy based on: the conditional rule, and an exception to the conditional rule based on the cybersecurity object; and
configure an admission controller of a software container cluster deployed in the computing environment to apply the contextual policy.
11 . A system for applying a cybersecurity contextual policy in a computing environment, comprising:
a processing circuitry; and
a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:
detect a cybersecurity object on a virtualization, the virtualization deployed in a computing environment;
detect a policy of the computing environment, the policy including a conditional rule;
generate a contextual policy based on: the conditional rule, and an exception to the conditional rule based on the cybersecurity object; and
configure an admission controller of a software container cluster deployed in the computing environment to apply the contextual policy.
12 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
configure the admission controller to apply the contextual policy on a plurality of software containers deployed in the software container cluster.
13 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
apply the policy to a code object, wherein the code object is utilized to deploy the virtualization.
14 . The system of claim 11 , wherein the conditional rule is any one of: an exclusionary rule, or an inclusionary rule.
15 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
detect a virtualization deployed in the computing environment which is an exception to the conditional rule; and
generate the exception based on a parameter of the detected virtualization.
16 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
intercept a request from a software container to an application programming interface (API); and
apply the contextual policy to the request.
17 . The system of claim 16 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
configure a webhook in the software container cluster to intercept requests from a container of a first node; and
configure the webhook to send the intercepted requests to the admission controller.
18 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:
configure a second admission controller of a second software container cluster deployed in a second computing environment to apply the contextual policy, wherein the second computing environment is deployed on a cloud computing infrastructure which is different than a cloud computing infrastructure on which the cloud computing environment is deployed.
19 . The system of claim 11 , wherein the admission controller is any one of:
a validating admission controller, a mutating admission controller, and a combination thereof.