Red Hat announced its plans to acquire StackRox and fold the startup's Kubernetes-native security technology into its OpenShift Kubernetes platform. Financial terms of the deal were not disclosed.

The vendor says this integration will further reduce the need for additional sensors in the stack and give customers a unified platform to more securely build, deploy, and run cloud-native applications across their entire fleet of Kubernetes clusters. It’s also part of Red Hat’s ongoing efforts to more fully form the OpenShift product that is becoming increasingly important to enterprises and Red Hat’s parent company IBM.

Red Hat said it will drive toward the full open sourcing of StackRox’s capabilities and continue to support StackRox usage on other platforms including Amazon Elastic Kubernetes Service (EKS), Microsoft Azure Kubernetes Service (AKS), and Google Kubernetes Engine (GKE) – an approach that echoes IBM’s hybrid cloud focus.

StackRox CEO Kamal Shah, in blog post, explained this purchase as an opportunity to “accelerate product innovation and achieve far greater scale, on a global level, than we would be able to achieve as an independent startup.”

Integration plans for Red Hat’s newly acquired technology will be made available after the acquisition closes, wrote Ashesh Badani, SVP of cloud platforms at Red Hat, in a separate blog post.  “The addition of StackRox to the Red Hat family is an important milestone in achieving Red Hat’s mission to create better technology the open source way,” Badani said. 

StackRox Container Security

StackRox is a 6-year-old company based in Mountain View, California that got its start just as the container craze began to gain momentum. It initially focused on runtime security for containers. However, overtime, customer feedback and industry trends identified Kubernetes growing popularity and StackRox’s new focus. 

Two years later, the company honed its craft and developed a Kubernetes-native security platform for cloud-native applications, containers, serverless, and Kubernetes to help DevOps and security teams communicate more efficiently.

In other words, the software simplifies security throughout the full container lifecycle from construction to deployment, monitoring performance, identifying problems, and provides analysts and incident responders with tools to make more informed security and compliance decisions. It does this by leveraging deep integration with Kubernetes to deliver visibility based on insights from code deployed on its platform.

Container Security Market

The cloud-native ecosystem continues to blossom as enterprises increasingly look toward taking greater advantage of their cloud infrastructure to speed up their internal operations and support for external services. However, that bloom has been impacted by the cloud of security concerns tied to nascent cloud-native technologies.

Most of those concerns are over misconfigurations and accidental exposure of access to their containerized environments, which made 2020 was a boon for cloud-native security startups, especially for those looking to be acquired by larger players looking to fill out their security platforms.

Fernando Montenegro, principal analyst for information security at 451 Research, part of S&P Global Market Intelligence, sees this latest Kubernetes-security transaction as "yet another signal that organizations are expecting that modern platforms will have the necessary security features for properly securing their workloads."

"This happens against the backdrop of the popular cloud providers – primarily AWS, Microsoft Azure, and Google Cloud, but also IBM Cloud, Oracle Cloud and Alibaba Cloud – spending significant resources on adding and improving security functionality within their offerings," Montenegro explained.

Red Hat's purchase marks the fourth Kubernetes security acquisition in less than a year: Cisco acquired Portshift, a 2-year-old startup that developed a Kubernetes-based platform to secure containers and serverless applications. VMware boosted its security portfolio by acquiring 3-year-old Kubernetes security startup Octarine; and Veeam purchased Kubernetes-orchestrated container data protection startup Kasten for $150 million in cash and stock.