Secure sidecar container
A secure side car (SSC) manager reads development artifacts and an application configuration file. Stubs and skeletons are created for inter-process communication between a main application and one or more SSC library containers, the stubs and skeletons based on SSC configurations specified in the application configuration file. Main application code is compiled for the main application. An application container image is created for the main application and a SSC image for each of the one or more SSC library containers. An application container corresponding to the application container image and a SSC library container corresponding to each SSC image or each of the one or more SSC library containers is deployed. A service mesh proxy, which controls network access for libraries within each SSC library container, is configured.
1 . A computer-implemented method, comprising:
reading, by a secure side car (SSC) manager, development artifacts and an application configuration file;
creating, by the SSC manager, stubs and skeletons for inter-process communication between a main application and one or more SSC library containers, the stubs and skeletons based on SSC configurations specified in the application configuration file, wherein the stubs provide local application programming interfaces (APIs) for remote functionality implemented by libraries in the one or more SSC library containers, and wherein the stubs are configured to marshal API parameters and send the API parameters to the skeletons in the one or more SSC library containers;
compiling, by the SSC manager, main application code for the main application, wherein compiling comprises linking the created stubs to the main application code;
creating, by the SSC manager, an application container image for the main application and a SSC image for each of the one or more SSC library containers;
deploying, by the SSC manager, an application container corresponding to the application container image and a SSC library container corresponding to each SSC image for each of the one or more SSC library containers; and
configuring, by the SSC manager, a service mesh proxy, which controls network access for libraries within each SSC library container and is configured to enable container specific network filtering.
2 . The computer-implemented method of claim 1 , wherein the development artifacts include one or more of application coding for the main application, configuration, and which libraries the main application can use, and wherein the application configuration file contains one or more of a configuration for the one or more SSC library containers, which libraries are configured to run in the one or more SSC library containers, and allowed destinations for the one or more SSC library containers.
3 . The computer-implemented method of claim 1 , wherein the compiling, by the SSC manager, main application code for the main application comprises adding stubs for transparent remote calls to containerized libraries.
4 . The computer-implemented method of claim 1 , wherein the application container image for the main application and the SSC image for each of the one or more SSC library containers is stored in a container registry.
5 . The computer-implemented method of claim 1 , comprising checking desired locations to permit containerized libraries to access against a corporate policy repository of trusted destinations.
6 . The computer-implemented method of claim 1 , wherein default network access for a SSC library container is no outbound communication allowed, no inbound communication from outside the SSC library container, and communication only with the application container.
7 . The computer-implemented method of claim 1 , comprising providing reporting functionality with respect to each SSC library container and associated libraries.
8 . A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations, comprising:
reading, by a secure side car (SSC) manager, development artifacts and an application configuration file;
creating, by the SSC manager, stubs and skeletons for inter-process communication between a main application and one or more SSC library containers, the stubs and skeletons based on SSC configurations specified in the application configuration file, wherein the stubs provide local application programming interfaces (APIs) for remote functionality implemented by libraries in the one or more SSC library containers, and wherein the stubs are configured to marshal API parameters and send the API parameters to the skeletons in the one or more SSC library containers;
compiling, by the SSC manager, main application code for the main application, wherein compiling comprises linking the created stubs to the main application code;
creating, by the SSC manager, an application container image for the main application and a SSC image for each of the one or more SSC library containers;
deploying, by the SSC manager, an application container corresponding to the application container image and a SSC library container corresponding to each SSC image for each of the one or more SSC library containers; and
configuring, by the SSC manager, a service mesh proxy, which controls network access for libraries within each SSC library container and is configured to enable container specific network filtering.
9 . The non-transitory, computer-readable medium of claim 8 , wherein the development artifacts include one or more of application coding for the main application, configuration, and which libraries the main application can use, and wherein the application configuration file contains one or more of a configuration for the one or more SSC library containers, which libraries are configured to run in the one or more SSC library containers, and allowed destinations for the one or more SSC library containers.
10 . The non-transitory, computer-readable medium of claim 8 , wherein the compiling, by the SSC manager, main application code for the main application comprises adding stubs for transparent remote calls to containerized libraries.
11 . The non-transitory, computer-readable medium of claim 8 , wherein the application container image for the main application and the SSC image for each of the one or more SSC library containers is stored in a container registry.
12 . The non-transitory, computer-readable medium of claim 8 , comprising checking desired locations to permit containerized libraries to access against a corporate policy repository of trusted destinations.
13 . The non-transitory, computer-readable medium of claim 8 , wherein default network access for a SSC library container is no outbound communication allowed, no inbound communication from outside the SSC library container, and communication only with the application container.
14 . The non-transitory, computer-readable medium of claim 8 , comprising providing reporting functionality with respect to each SSC library container and associated libraries.
15 . A computer-implemented system, comprising:
one or more computers; and
one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations, comprising:
reading, by a secure side car (SSC) manager, development artifacts and an application configuration file;
creating, by the SSC manager, stubs and skeletons for inter-process communication between a main application and one or more SSC library containers, the stubs and skeletons based on SSC configurations specified in the application configuration file, wherein the stubs provide local application programming interfaces (APIs) for remote functionality implemented by libraries in the one or more SSC library containers, and wherein the stubs are configured to marshal API parameters and send the API parameters to the skeletons in the one or more SSC library containers;
compiling, by the SSC manager, main application code for the main application, wherein compiling comprises linking the created stubs to the main application code;
creating, by the SSC manager, an application container image for the main application and a SSC image for each of the one or more SSC library containers;
deploying, by the SSC manager, an application container corresponding to the application container image and a SSC library container corresponding to each SSC image for each of the one or more SSC library containers; and
configuring, by the SSC manager, a service mesh proxy, which controls network access for libraries within each SSC library container and is configured to enable container specific network filtering.
16 . The computer-implemented system of claim 15 , wherein the development artifacts include one or more of application coding for the main application, configuration, and which libraries the main application can use, and wherein the application configuration file contains one or more of a configuration for the one or more SSC library containers, which libraries are configured to run in the one or more SSC library containers, and allowed destinations for the one or more SSC library containers.
17 . The computer-implemented system of claim 15 , wherein the compiling, by the SSC manager, main application code for the main application comprises adding stubs for transparent remote calls to containerized libraries.
18 . The computer-implemented system of claim 15 , wherein the application container image for the main application and the SSC image for each of the one or more SSC library containers is stored in a container registry.
19 . The computer-implemented system of claim 15 , comprising checking desired locations to permit containerized libraries to access against a corporate policy repository of trusted destinations.
20 . The computer-implemented system of claim 15 , wherein default network access for a SSC library container is no outbound communication allowed, no inbound communication from outside the SSC library container, and communication only with the application container.
21 . The computer-implemented system of claim 15 , comprising providing reporting functionality with respect to each SSC library container and associated libraries.