Cloud security company Fugue this week debuted a platform that unifies infrastructure as code (IaC) and cloud runtime security using a single set of policies.
This ensures consistent security policy enforcement and also saves developers and cloud security teams time, Fugue co-founder and CEO Josh Stella said. Usually, these teams need to use two sets of policies — and two different languages — to secure both infrastructure as code and cloud runtime environments.
“It’s a duplication of efforts,” he said. “So, for example, you might have to write your infrastructures-as-code policies in Python, and then write your runtime monitoring policies in a SQL derivative, which is what one of our main competitors has their customers doing.”
This main competitor is Palo Alto Networks and its Prisma Cloud security platform, Stella added.
“We’ve already won a number of customers on this single feature alone,” he said. While some Fugue customers already use its open-source version of IaC and cloud runtime security, this unified policy feature is now fully integrated into its enterprise-grade software-as-a-service platform. The IaC platform with the new unified policy engine can ensure cloud security across development and operations using 50% fewer engineering resources, Stella added.
“This particular issue is really thorny for folks because if you have to write two code bases to do the same thing in two different languages, they’re always going to be out of sync, and they’re never really going to get the same result,” Stella said.
Open Policy Agent Powers Fugue IaCIt also creates friction between the security and developer teams because they aren’t on the same page policy-wise, Stella added. “Whereas with Fugue, you author a single policy using Open Policy Agent and no proprietary languages," he explained. "And that same policy will check pre-deployment, so your developers can use it very easily as a natural part of their workflow, but then it can also be used by the security team to monitor the running environment once it’s deployed. That’s unique in the industry.”
Open Policy Agent (OPA) is the open standard for policy as code and a Cloud Native Computing Foundation graduated project. Fugue’s new unified policy engine uses OPA and Regula, which is the vendor’s open source implementation of OPA for IaC and cloud security.
Fugue IaC supports pre-deployment security checks for Terraform (HCL and plan files), Amazon Web Services CloudFormation (YAML, JSON, AWS CDK, or composed by hand), Kubernetes manifests, and Dockerfiles. Developers can use Fugue to generate interactive visual maps of their IaC templates and export IaC diagrams to use for planning and approval processes.
Shifting Security LeftThe ongoing move to shift security left in the development process, and secure code before it’s deployed, “is at the heart of driving this” new platform, Stella said. Fugue secures millions of resources for customers including AT&T, SAP, and Red Ventures, and it aims to reduce friction between developers and security teams.
“You can build things much faster in the cloud than you can in the data center,” Stella said. “With the cloud, I can build a global network in five minutes. What that means is: As a developer, I’m going to build global networks in five minutes. If you give me that power, I’m gonna use it to fulfill the business goals of the organization.”
But this means the security team doesn’t have much time to catch flaws and vulnerabilities before the development. “Security in the cloud is largely architectural, and you have to catch those things when the developers are building the cloud apps, not once they’re deployed,” Stella said. “You need to monitor them once they’re deployed, but you need to catch it early.”
Fugue IaC essentially automates the security team’s voice via policies as code, he added. “And what that does is it allows the organization to operate really fast to build networks in five minutes, but in a way that doesn’t break the security policies of the organization.”
Comments