
Automate Kubernetes Network Policies With Otterize Intents?
Source: YouTube · DevOps & AI Toolkit · published Jun 12, 2023 · 18:21
The video explains three approaches to network trust in Kubernetes and introduces Otterize, which automates network policies through intent specifications 0:06-0:20. While zero trust requires manual approval for connections, creating bottlenecks, Otterize allows applications to declare connection intent 3:08-3:30.
Key Takeaways:
• Three trust models: trust everyone (insecure), trust no one (zero trust), or trust internal teams but not outsiders 0:06-0:20
• Traditional network policies create bottlenecks as destination owners must approve all incoming connections 2:39-3:08
• Otterize automatically generates network policies based on declared intents without requiring destination owner approval 7:15-8:09
Otterize is ideal for organizations that trust internal teams while securing against external threats 16:46-17:03.
Sources:
- 0:06-0:20 Introduction to three types of companies regarding trust
- 2:39-3:08 Traditional network policy approach
- 7:15-8:09 Otterize's intent-based approach
- 16:46-17:03 Best use cases for Otterize
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
foreign [Music] there are three types of companies when trust is concerned first we have those who trust everyone those are the companies that hope for the best those are the companies that do not secure their systems either because they do not know how to do it or because they do not care so what does that mean in the context of network policies well that means that any application inside the system can freely communicate with any other application it does not matter whether an app was deployed by one team or another it does not matter if someone from outside our organization managed to start a malicious process that tries to communicate with other apps in the system and gather information it shouldn't or it tries to create a denial of service attacks from inside the cluster or tries to d…