The cloud-native ecosystem continues to blossom as enterprises increasingly look toward taking greater advantage of their cloud infrastructure to speed up their internal operations and support for external services. However, that bloom has been impacted by the cloud of security concerns tied to nascent cloud-native technologies.

Much of the growth around cloud-native adoption has been tied to the boom around Kubernetes, which has grown from being the de facto container orchestration it initially was developed to be to now being the soil from which nearly everything cloud native grows. But with this growth has come greater scrutiny over securing Kubernetes-based platforms.

“With a lot of adoption, it’s natural that the security factors become critical because now they're suddenly very large production loads on this and the world's starting to depend more and more on cloud native. So the security pieces get very important,” explained Priyanka Sharma, who recently took over as GM of the Cloud Native Computing Foundation (CNCF), which houses the Kubernetes project.

CNCF’s 2019 community survey found that security was the second biggest challenge faced by organizations in deploying containers. Forty percent of those surveyed cited that challenge, which came in just behind cultural changes they see with their development teams.

“Many of the tools they have been using for years — those that were designed to ensure security and performance of monolithic applications running on a relatively simple, vertical stack — no longer suffice in complex environments that are increasingly composed of containers, microservices, third-party services, and multiple clouds,” noted 451 Research in an enterprise report on cloud-native security. “The trade-off for agility gains is sheer complexity: the scale in the number of components that can be tracked for what is essentially similar functionality can jump one or two orders of magnitude.”

Security Challenges

The tale of Kubernetes-related security issues is complex. Numerous bugs have been found throughout its existence — something that experts said is to be expected.

In fact, one was found earlier this month that impacted the Kubernetes controller manager. If breached, the flaw could allow an attacker to gain access to data from services connected to the host network of the cluster’s manager.

“There are always going to be vulnerabilities,” Rani Osnat, VP of strategy and product marketing at Aqua Security, said in an interview with SDxCentral on the heels of the discovery of a large security bug within the platform in late 2018. “The fact that one was found was to be expected. And I expect more will be found going forward. That’s just what should be expected with software.”

The Kubernetes project itself has had an arms-length relationship when it comes to the embedded security posture of the platform, often leaving the real hardening to other cloud-native projects or the vendor community. This has allowed the Kubernetes team to focus on what the platform is supposed to do and left the security angle to the experts.

Aaron Crickenberger, who was release lead for the Kubernetes 1.14 update last year, explained to SDxCentral that the Kubernetes community does not view security as something tied to specific updates and instead is “something to be continually evaluated and improved.”

Despite that approach, the CNCF, which also hosts dozens of other leading cloud-native platforms, has more broadly looked to plug the security gap in cloud-native platforms. It hosts numerous cloud-native security projects like TUF, Falco, and Notary, and has those platforms in use by a number of security vendors like Snyk, StackRox, Sysdig, Alcide, and Aqua Security.

This focus on cloud-native security has also increased financial interest in the market. Cloud native-focused security vendors have been snapped up recently by larger players looking to fill out their security platforms.

One example was VMware’s recent purchase of Kubernetes security startup Octarine. VMware is integrating Octarine into its rapidly expanding Tanzu platform.

“Every CISO that I talk to, every chief security officer I talk to, says that they need help in this area — in containers,” Patrick Morley, SVP and GM for VMware Carbon Black, recently told SDxCentral.

Compared to building legacy workloads — requesting hardware from IT, buying new software, and waiting for all the pieces to arrive and come together — it’s really easy for developers to use a company credit card, spin up a public cloud instance, and start building container-based applications.

“And so what happens is one day the CIO wakes up and says, ‘holy smokes, we have 4,000, 5,000 containers and no one had any idea. I have no idea if they’re configured correctly,’” Morley said. “So they go to the CISO and say ‘go solve this.’”

To Error Is Human

As with most things, the biggest gap in securing cloud-native platforms is at the human level.

A report earlier this year from StackRox found that human error and misconfigurations were the primary culprits for Kubernetes security issues. The security firm tapped 451 Research to conduct the research, which found that 94% of respondents experienced at least one container security incident in the past 12 months. Consequently, 44% of respondents were then delayed in moving their applications into production because of security concerns in what StackRox’s VP of marketing Michelle McLean called “two likely related findings.”

And CNCF last year released its first security audit of Kubernetes. That internal look found 37 vulnerability issues with the 1.13.4 iteration of Kubernetes. These included five high-severity issues and 17 medium-severity issues.

The overall size and operational complexity of Kubernetes was cited as being a key reason for these security holes.

“The assessment team found configuration and deployment of Kubernetes to be non-trivial, with certain components having confusing default settings, missing operational controls, and implicitly defined security controls,” the audit explained.

It also found that the extensive Kubernetes codebase lacks detailed documentation to guide administrators and developers in setting up a robust security posture.

“The codebase is large and complex, with large sections of code containing minimal documentation and numerous dependencies, including systems external to Kubernetes,” the audit noted. “There are many cases of logic re-implementation within the codebase, which could be centralized into supporting libraries to reduce complexity, facilitate easier patching, and reduce the burden of documentation across disparate areas of the codebase.”

While CNCF took the lead on the audit process, CNCF COO Chris Aniszczyk explained that it was not really up to the organization to take the lead on mandating the security posture of projects like Kubernetes.

“It’s not necessarily the role of the community to ship out all of the latest security fixes, that’s really the role of the member companies to do,” Aniszczyk said. “But we do want to provide the knobs to make that easier.”

He did add that CNCF has recently set up a new security group that will look to drive audit recommendations back into the organization’s projects. And that the community was moving to beef up security options in upcoming Kubernetes releases.

Telecom Push

This security focus is only going to intensify as cloud-native platforms begin to be adopted by telecommunication providers. These providers need to add protection of what are public safety platforms like emergency calls that are routed over their increasingly cloudified networks.

Operators have for years been wanting to dig more deeply into the cloud-native ecosystem to increase the agility of their network deployments. But, they need granular security controls that can be tweaked to deal with individual microservices that will run in cloud native functions (CNFs), and they need that control to be built into their current workflow.

“Apart from the known vulnerabilities in the open-source components used to develop the 5G CNFs, most CNF threats are actually unknown, which is riskier,” wrote Pramod Nair, consulting systems engineer for security at Cisco, in a recent blog post. “The deployment model of CNFs in the public and private cloud brings in another known, yet the widespread problem of inconsistent and improper access control permissions putting sensitive information at risk.”

These challenges are not likely to rain on the cloud-native parade, but they are significant hurdles the ecosystem will need to account for in order for that parade to maintain its momentum.