Red Hat introduced a series of new security capabilities this week during its annual summit to advance security across open hybrid cloud environments.
The vendor announced a software supply chain security pattern, delivered via its OpenShift platform to simplify the security feature implementation in the build, deploy, and run process.
The pattern uses a Kubernetes-native pipeline through OpenShift Pipelines and GitOps for version control and integrates with open source project Sigstore through Tekton Chains to make the cryptographic signing of code more accessible.
Red Hat also offered a technical preview of Ansible content signing technology from its Ansible Automation Platform 2.2, which enables automation content validation for software supply chain security.
“We're keeping up with changes in cryptographic standards,” Kirsten Newcomer, director of security product management at Red Hat, told SDxCentral. “We also really want to help them build security into the CI/CD pipelines that they're using to manage their applications.”
She noted the SolarWinds hack, followed by the executive order from the Biden administration last May, led to increased recognition of the importance of supply chain security, so Red Hat also pays strong attention to it.
“Many customers that we work with are already doing vulnerability scanning in their pipelines. But when we think about supply chain security, it goes beyond that,” Newcomer argues. The new pattern “allows our customers to more easily deploy and work with an out-of-the-box pipeline that has security gates integrated into it.”
Red Hat Doubles Down on Edge SecurityIn addition to the software supply chain, another key area for Red Hat is edge deployment, Newcomer noted. “We have a wide range of customers in that space, strong customer base in telco, but also customers in retail where edge can be point of sale.”
Because of this, Red Hat unveiled several improvements to its Red Hat Advanced Cluster Security for Kubernetes services.
The service aims to protect container workloads running on edge devices. The new additions include automated DevSecOps through vulnerability management, application configuration analysis, and CI/CD integration; threat detection and incident response capabilities at runtime; and network segmentation.
Red Hat also introduced RHEL 9 (Red Hat Enterprise Linux 9), which is the latest iteration of its long-running enterprise Linux platform. It uses integrity measurement architecture (IMA) at the kernel level to verify individual files and their provenance, which helps detect accidental and malicious modifications to systems and offers more remediation capabilities.
Comments