Weaveworks is adding automated firewall placements to its container networking, boosted by a new feature in the Kubernetes container orchestration platform.
Kubernetes 1.4, released yesterday, includes the ability to assign security policies to containers. Weaveworks subsequently assigns those policies to the networks it creates.
"When a new container is started, we know what policy it matches, so we can start the firewall rules for that container," says Mathew Lodge, Weaveworks' chief operating officer.
The firewall that's being activated isn't anything fancy; it's code that's available with any Linux distribution.
The new capability is part of Weave Net 1.7, released today. Weave Net handles network virtualization among containers, creating a network out of VXLAN tunnels.
Weave Net is available as open source code. It can also be used as a Docker networking plug-in or a Kubernetes Container Network Interface (CNI) plug-in.
Weaveworks' commercial aspirations are based on Weave Cloud, a hosted cloud service that can run Docker containers on Amazon Web Services (AWS). Weave Cloud is in public beta and due to reach general availability by the end of the year.
Comments