Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z...

21
IBM Cloud / DOC ID / Month XX, 2018 / © 2018 IBM Corporation Bezpieczeństwo platformy OpenShift z wykorzystaniem IBM Cloud Marcin Spychała Client Technical Professional

Transcript of Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z...

Page 1: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

IBM Cloud / DOC ID / Month XX, 2018 / © 2018 IBM Corporation

Bezpieczeństwo platformy OpenShiftz wykorzystaniem IBM Cloud—Marcin SpychałaClient Technical Professional

Page 2: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

2

Page 3: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

3IBM Cloud / DOC ID / Month XX, 2018 / © 2018 IBM Corporation

Znalezienie jasnych zaleceń nie jest łatwe …

Page 5: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

5

Zalecenia

IBM Cloud Security Advisor

Page 6: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

Dodatkowe integracje

6

Zalecenia

Page 7: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

Problemy i zalecenia

7

Zalecenia

Page 8: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

Możliwości platformy

8

Narzędzia

Page 9: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

9

Narzędzia

Page 10: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

10

Narzędzia

Page 11: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

11

Narzędzia

Page 12: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

12

Trusted computing - platforma

https://cloud.ibm.com/docs/openshift?topic=openshift-security#threats

Page 13: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

13

Trusted computing - architektura

https://www.ibm.com/cloud/architecture/architectures/securityArchitecture

Page 14: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

Nie chcę Chmury

https://ibm.box.com/s/mpzwilyna0wnyg5aizf67een93pak044

Page 15: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

15

Czego się spodziewać

Page 16: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

16

Typowe zagrożenia dla platformy

Page 17: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

17

IBM Cloud Security Services - przegląd

Page 18: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

18

Czym IBM Cloud zarządza za Ciebie

▸ Automated provisioning and configuration of Infrastructure (compute, network and storage)

▸ Automated installation and configuration of OpenShift, including HA cross zone configuration

▸ Automatic upgrades of all components (operating system, OpenShift components, and in cluster services)

▸ Security patch management for OS and OpenShift

▸ Automatic failure recovery for OpenShift components and worker nodes

▸ Automatic scaling of OpenShift configuration

▸ Automatic backups of core OpenShift ETCD data

▸ Built in integration with cloud platform - monitoring, logging, KeyProtect, IAM, ActivityTracker, Storage, COS,

Security Advisor, Service Catalog, Container Registry and Vulnerability Advisor

▸ Built in Load Balancer, VPN, Proxy, Network edge nodes, Private Clusters and VPC capabilities

▸ Built-in Security including image signing, image deployment enforcement, and hardware trust

▸ 24/7 global SRE team to maintain the health of the environment and help with OpenShift

▸ Global SRE has deep experience and skill in IBM Cloud Infrastructure, Kubernetes and OpenShift,

resulting in much faster problem resolution

▸ Automatic compliance for your OpenShift environment (HIPAA, PCI, SOC2, ISO)

▸ Capacity expansion through a single click

▸ Automatic multi-zone deployment in MZRs, including integration with CIS to do cross zone traffic routing

▸ Automatic Operating System performance tuning and security hardening

Page 19: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

19

Porównanie

Page 20: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

IBM Cloud / DOC ID / Month XX, 2018 / © 2018 IBM Corporation

To już nie ”początek drogi” – to stare dobre małżeństwo

Page 21: Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud · Bzzńw platformy OpenShift z wykorzystaniem IBM Cloud ... Service Catalog, Container Registry and Vulnerability Advisor ...

21

Sprawdź nas!

https://cloud.ibm.com/kubernetes/overview?platformType=openshift