Cloud-native security vendor Armo today announced the integration of ChatGPT into its platform to help organizations ease Kubernetes cluster security and enforce security policies.

Armo CTO Ben Hirschberg told SDxCentral the integration gives users three main advantages: a completed open policy agent (OPA) rule created by ChatGPT, a natural language description of what each rule does, and suggested remediation to fix failed controls. "Users can just describe in words what they want a security control to check, and they have the option to include the file or structure they want to be checked, but it's not required," he explained.

Successfully securing Kubernetes clusters in modern distributed environments can be done using security policies like OPA rules based on controls that scan for configuration files, workloads, container images, and API servers, for example. Hirschberg highlighted OPA rules that use the Rego programming language – "a language for writing security controls – but it's very niche. People don't know it and don't use it."

To that point, Armo and its Kubescape security scanner use Rego-based OPA rules to provide "loads of security controls ready to use out-of-the-box, specifically those required by popular security frameworks like CIS, NSA and MITRE," Hirschberg said.

Cloud-native security experts often want or need to write custom security policies and controls based on differentiated needs. "At the moment, they need to know how to use OPA and Rego, which isn’t a trivial task. This is where ChatGPT comes in," he explained.

The integration allows users to create custom controls without needing to understand how to use OPA or the Rego language. "All they need to do is to write in their own words what they want to check, and ChatGPT and Armo will return the exact control written in Rego, with the description and suggested remediation," Hirschberg said. It goes beyond just in-platform access to OpenAI's natural language processor; it "adds more information, background, context, etc., about OPA and Rego to ensure that ChatGPT produces the right answer in the right language and syntax."

Armo Eyes Generative AI Expansions

Armo plans to add additional generative artificial intelligence (AI) use cases aimed at strengthening and simplifying Kubernetes security. Hirschberg highlighted role-based access control (RBAC) as a priority area for Armo, despite its tenure as "one of the most complex and confusing areas in Kubernetes security," he said. "We see a few interesting ways that AI like ChatGPT could really help to make RBAC simple and easy."

While ChatGPT won't completely eliminate the need for security teams to learn programming languages, "for sure it can expedite the learning curve of how to use languages and how to get the most out of them," Hirschberg said. For example, users will need to understand enough to check if the code produced by ChatGPT is accurate and provides the expected result. But as generative AI models become more accurate and precise, "users might feel confident to completely rely on the code they generate," he noted.

The Armo team anticipates as more users create custom controls, they'll also contribute some to the Kubescape open source security scanner adopted by the Cloud Native Computing Foundation (CNCF) last month, "so all the community can benefit from them," Hirschberg said.