VMware today announced container runtime security capabilities that build upon its Carbon Black Cloud platform for endpoint and workload security. 

The vendor initially released the Carbon Black Cloud platform in late 2020, designed to provide visibility into on-premises and public cloud Kubernetes clusters to help identify misconfigurations and other security risks. Its capabilities came from the Kubernetes security startup Octarine that VMware acquired two years ago. Early last year, VMware extended the platform to support container image scanning and hardening. 

The newly released runtime security features for the Carbon Black Cloud include runtime cluster image scanning, Kubernetes visibility mapping, workload anomaly detection, egress and ingress security, and threat detection. Combined with the existing compliance and hardening, the platform can help security and DevOps teams to secure containers throughout the full application lifecycle, VMware claims.

“Protecting the runtime is the foundation of securing the inner workings of a modern application,” Tom Gillis, SVP and GM at VMware's networking and advanced security business group, said in a statement. With the new features, “our end-to-end security offering is now tightly integrated across the entire application lifecycle, protects all east-west traffic, and brings a new level of distributed visibility and security to APIs.”

Carbon Black Cloud Automates Runtime Vulnerability Scanning 

Carbon Black Cloud’s existing vulnerability management tool scans all container images to identify security risks at the time of build before they are deployed into production. On top of it, the container runtime security service expands the image scanning feature to the Kubernetes clusters, whether they are on-premises or in the cloud.

It means that security and DevOps teams are no longer restricted to the images that go through the continuous integration, continuous delivery (CI/CD) pipeline and can instead scan images through runtime. 

The ability gives teams “visibility to vulnerabilities in images … deployed from any third-party registries,” VMware’s Oren Penso and Ram Akuka wrote in a blog post, adding that “by giving the user control to customize their scan, security teams can introduce automated, custom policies and be notified when those policies have been violated.”

The company also integrates Carbon Black Cloud with its Tanzu services to better secure applications and simplify operations for those teams. 

“Our goal is to enable security leaders to enforce the same zero-trust design principles for secure workload access across their virtualized and modern application deployments,” Penso and Akuka wrote. 

The container runtime protection capabilities are available through VMware Carbon Black Cloud Container Advanced Bundle.