SECURED CONTAINER MANAGEMENT
A method of securing containers within clusters is disclosed. The method includes configuring service access points within clusters as secure endpoints; associating services within clusters with secure identities to constrain which communities-of-interest can reach which services; and wherein each cluster is cryptographically isolated such that no information will leak in or out of the cluster through an associated network.
1 . A method of securing containers within clusters, the method comprising:
configuring service access points within clusters of containers as secure endpoints, which handle all communications into and out of the cluster; and
associating services within the clusters with secure identities to constrain which communities-of-interest can reach which services;
wherein each cluster is cryptographically isolated such that no information will leak in or out of the cluster through an associated network.
2 . The method of claim 1 , further comprising encrypting communications within communities of interest with a key associated with the communities of interest.
3 . The method of claim 1 , wherein associating includes communities of interest configured for a web tier, an application tier or a database tier.
4 . The method of claim 1 , configurating service access points includes configuring a service access point as a node within a cluster.
5 . The method of claim 1 , wherein associating services includes associating services within the clusters as a community of interest.
6 . The method of claim 1 , further comprising translating by the secure endpoints between communities of interest outside the cluster and communities of interest within the cluster.
7 . A system operating on an apparatus having a memory and a processor coupled to the memory, system comprising:
service access points within clusters of containers configured as secure endpoints to handle all communications into and out of the cluster; and
services within the clusters having secure identities to constrain which communities of interest can reach which services;
wherein each duster is cryptographically isolated such that no information will leak in or out of the cluster through an associated network.
8 . The system of claim 7 , further wherein the secure endpoints encrypt, communications within communities of interest with a key associated with the communities of interest.
9 . The system of claim 7 , wherein communities of interest can be configured for a web tier, an application tier or a database tier.
10 . The system of claim 7 , wherein a service access point is a node within a cluster.
11 . The system of claim 7 , wherein services within the clusters are part of a community of interest.
12 . The system of claim 7 , wherein he secure endpoints translate between communities of interest outside the cluster and communities of interest within the cluster.
13 . A computer program product, comprising:
a non-transitory computer readable medium comprising instructions which, when executed by a processor of a computer system, cause the processor to perform the steps of:
configuring service access points within clusters of containers as secure endpoints, which handle all communications into and out of the cluster; and
associating services within the clusters with secure identities to constrain which communities-of-interest can reach which services;
wherein each cluster is cryptographically isolated such that no information will leak in or out of the cluster through an associated network.
14 . The computer program product of claim 13 , further comprising encrypting communications within communities of interest with a key associated with the communities of interest.
15 . The computer program product of claim 13 , wherein associating includes communities of interest configured for a web tier, an application tier or a database tier.
16 . The computer program product of claim 13 , configurating service access points includes configuring a service access point as a node within a cluster.
17 . The computer program product of claim 13 , wherein associating services includes associating services within the clusters as a community of interest.
18 . The computer program product of claim 13 , further comprising translating by the secure endpoints between communities of interest outside the cluster and communities of interest within the cluster.