Google released a beta version of its Shielded GKE Nodes that it says prevents an attacker from gaining persistent access to user code or data by exploiting vulnerable Kubernetes nodes.

The Google angle hardens the underlying Google Kubernetes Engine (GKE) node against rootkits and bootkits. These are software tools that allow an attacker to gain undetected control of a compute system. Google noted that such a vulnerability was exploited last year when a researcher was able to gain full access to a Kubernetes cluster.

The Shielded GKE Nodes provides a cryptographically verifiable check to make sure the node operating system (OS) is running on a virtual machine (VM) in a Google data center; uses secure and measured boot, virtual trusted platform module (vTPM), UEFI firmware, and integrated monitoring to provide increased protection against rootkits and bootkits in a node; and is built on the Trusted Computing Group’s (TCG) Trusted Platform Module to verify the boot integrity of the node and bolster the node bootstrapping process.

The Google offering also taps into its Compute Engine Shielded VM, which the company released earlier this year at its Google Next event.

The Shielded GKE Nodes is available for free to GKE customers and is available in all regions for Ubuntu and Container Optimized OS node images running at least GKE version 1.13.6.

Kubernetes Nodes and Container Security

Container security remains a serious consideration for enterprises. Gartner forecasts that more than 75% of global companies will use containers in production by 2022, compared to less than 30% today.

A recent survey from StackRox found that while two-thirds of organizations are running more than 10% of their applications in a containerized environment, 40% of those organizations think their current security stance is not adequate to protect those environments.

Most of those concerns are over misconfigurations and accidental exposure of access to their containerized environments. However, a robust 43% stated concerns over runtime security, 35% specified concerns about deployment security, and 22% said they were worried about build security.

“Just as with securing [infrastructure-as-a-service], missing container and Kubernetes security best practices and human error in misconfigurations create real threats to organizations and their bottom lines,” said Mark Bouchard, co-founder and CEO of AimPoint Group, in a statement on the report. “The consequences of overlooking security early in the container life cycle will be steep, both in lost time and money and in risk of exploitation.”

The Google move also comes on the heels of a Cloud Native Computing Foundation (CNCF) security audit that found dozens of security vulnerabilities in the Kubernetes container orchestration platform. These included five high-severity issues and 17 medium-severity issues. Fixes for those issues have already been deployed.

M&A Impact

Container security concerns are also fueling mergers and acquisitions.

McAfee last month purchased 4-year-old startup NanoSec for an undisclosed amount to boost its container security capabilities. NanoSec’s platform provides agentless container scanning and configuration audits.

That followed Palo Alto Networks’ $410 million acquisition of container-focused security provider Twistlock in May.