+ All Categories
Home > Documents > people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull...

people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull...

Date post: 18-Oct-2020
Category:
Upload: others
View: 1 times
Download: 0 times
Share this document with a friend
17
Transcript
Page 1: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED
Page 2: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED
Page 3: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED
Page 4: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED
Page 5: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED

RED HATENTERPRISE LINUX

ATOMIC HOST

Page 6: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED

WHAT ARE LINUX CONTAINERS?Software packaging concept that typically includes an application and all of its runtime dependencies.

● Easy to deploy and portable across host systems

● Isolates applications on a host operating system

● In RHEL, this is done through:– Control Groups (cgroups)

– kernel namespaces

– SELinux, sVirt– Docker

HOST OS

SERVER

CONTAINER

LIBS

APP

Page 7: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED

7

Traditional OS Containers

TRADITIONAL OS VS. CONTAINERS

HARDWARE

HOST OS

HARDWARE

HOST OS

CONTAINER

LIBS

APP A

LIBS A LIBS B LIBS LIBS

APP A APP B

CONTAINER

LIBS

APP B

Page 8: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED

ESTABLISHING STANDARDS AROUND...

REGISTRY / CONTAINER DISCOVERY

CONTAINER FORMAT WITH DOCKER

ISOLATION WITH LINUX CONTAINERS

ORCHESTRATION WITHKUBERNETES

Red Hat works with the open source community to drive standards for containerization.

Page 9: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED

INSERT DESIGNATOR, IF NEEDED9

CONTAINERS YOU CAN

TRUST

PROVEN CONTAINER

PORTABILITY

INTEGRATEDAPP DELIVERY

PLATFORM

TRANSFORMING APP DELIVERYCONTAINERS FOR THE ENTERPRISE

Page 10: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED

CONTAINER PORTABILITYACROSS PHYSICAL, VIRTUAL, PRIVATE CLOUD, PUBLIC CLOUD

7

APPLICATION LIFECYCLE PORTABILITY

ENVIRONMENT RUN-TIME PORTABILITY

PHYSICAL VIRTUAL PRIVATE CLOUD PUBLIC CLOUD

Page 11: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED

TRUST

Page 12: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED

● Who built this image?● What’s its purpose? Was

it created to support a demo?

● Is it safe to consume?● Who maintains it?

NEED FOR A “CHAIN OF TRUST”

DOCKER HUB

docker pull mongodb

Page 13: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED

13

SECURING HOSTS AND CONTAINERSRED HAT CONTAINER CERTIFICATION

UNTRUSTED ● How can you validate what’s in the host and

the containers? Will it compromise your infrastructure?

● It “should” work from host to host, but can you be sure?

CERTIFIED ● Trusted source for the host and the

containers● Enterprise life cycle for container content● Proven portability● Container Development Kit

HOST OS

HARDWARE

CONTAINER

LIBS

APP

CONTAINER

LIBS

APP

HOST OS

HARDWARE

CONTAINER

LIBS

APP

CONTAINER

LIBS

APP

Page 14: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED

SIMPLIFYING CONTAINER ADOPTIONFOR PARTNERS

Page 15: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED

INTEGRATEDAPPLICATION DELIVERY

PLATFORM

Page 16: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED

RED HAT PARTNER SOLUTIONS

RED HATSATELLITE

RED HATCLOUDFORMS

SINGLE APP DELIVERY PLATFORM VIA CONTAINERSdevelop, deploy, operate

OPENSHIFTby Red Hat

RED HAT ENTERPRISE LINUX 7

RED HAT ENTERPRISE LINUXATOMIC HOST

MANY CONTAINER SOURCES (trusted and untrusted)

PUBLIC REGISTRIES such as Docker Hub

PRIVATE REGISTRIESon premise

CERTIFIED IMAGESRed Hat Customer Portal

DEPLOYMENT

MANAGEMENT

MULTIPLE DEPLOYMENT TARGETSon Red Hat certified hardware, hypervisors and CCPs

DEVELOPMENT

ORCHESTRATIONof containers and microservices

OPENSHIFT

CERTIFIEDISV APPS

ATOMIC APPLICATION ARCHITECTUREMORE THAN THE CONTAINER

Page 17: people.redhat.compeople.redhat.com/mlessard/qc/presentations/june2015/Atomic-Host… · docker pull mongodb. 13 SECURING HOSTS AND CONTAINERS RED HAT CONTAINER CERTIFICATION UNTRUSTED

Recommended