Red Hat today announced the StackRox community, which is the first step on the path toward to a fully open source, Kubernetes-native security platform.

Red Hat acquired the Kubernetes security startup earlier this year, and late last month rolled out Advanced Cluster Security for Kubernetes, which is based on StackRox technology. This security technology is also built into Red Hat’s OpenShift Platform Plus, which makes good on Red Hat’s pledge to integrate StackRox’s security technology with its OpenShift Kubernetes platform.

Additionally, when Red Hat announced its deal to buy StackRox, the vendor said it would move toward full open sourcing of StackRox’s capabilities. “We’re still at the initial stages of working toward that,” said Wei Lien Dang, senior director of product and marketing for cloud platforms at Red Hat. He also is the former co-founder and CSO of StackRox.

While there’s not an open source product available at launch, the new StackRox community will manage the future project, he explained. “Red Hat is certainly very familiar with the open sourcing process, and what you’ll see over the coming months is participation with other relevant upstream communities,” Dang said. The company will also make more of the StackRox code available to the open source community, “but it is a process that involves both technical and legal considerations, and we want to be thoughtful about how we do it,” he added.

Shortly before the acquisition, in October 2020, StackRox launched KubeLinter, an open source project that analyzes Kubernetes YAML files and Helm charts for correct configurations, with a focus on enabling application production readiness and security earlier in the development process. This move, in part, inspired the decision to open source StackRox, Dang explained.

“We want to build on that momentum and interest we saw around KubeLinter,” he said. “If you look at the cloud native ecosystem in particular, there have been open source security projects, but they’re typically focused on specific areas. For instance, you might have a project for image scanning, or a project for policy, or a project for another different use case.”

StackRox, however, aims to provide “a fully open source, comprehensive security solution, because it comes out of the StackRox software, which addresses multiple use cases,” Dang said, adding that the new community will “continue that conversation around what a Kubernetes-native security might look like.”

While RedHat hasn’t yet decided which group will ultimately assume governance of the open source StackRox project, it sounds like the Cloud Native Computing Foundation (CNCF), which also houses Kubernetes, is a safe bet. “I think CNCF or related committees would definitely be ones that we would look to, and part of that just doing the right thing for the ecosystem,” Dang said. “If you look at where the bulk of projects you are going in terms of governance, we definitely want to align with that. We don’t want to do something that is counter to that at all.”

Why StackRox Community Is a Big Deal for Security

There are a couple reasons why a Kubernetes-native open source security project is a big deal to the broader security industry.

“Traditionally, the security industry has been marked by many different proprietary solutions or products that had primarily closed code bases,” Dang said. “And so this is really an opportunity to build on the work that the Kubernetes and CNCF community have already started to make things more open around security.”

Additionally, most other cloud-native security tools focus on single use cases such as container security, Dang added. “This is about open sourcing a solution that is Kubernetes-native from the ground up, which means that we integrate and extend the native controls in Kubernetes and apply them to all these different areas of security.”