Cloud Native
Security Talks
RSS

KubeCon Europe 2018

OPA: The Cloud Native Policy Engine

Torin Sandall, Styra

Abstract

How does your organization control “who can do what” across the stack? How do you enforce auth/z, admission control, and risk management policies in your micro-services, orchestrators, and CI/CD systems? How do you implement low-latency policy enforcement in the polyglot environments that your company depends on? In this talk we introduce the Open Policy Agent (OPA) project. OPA is an open source policy engine used by companies like Netflix and Medallia to enforce rules consistently, up and down the stack. We will showcase OPA features like hot-reload, tracing, and optimizations with demos of auth/z and admission control policies. Finally we will show how to integrate your services with OPA and provide examples of integrations for projects like Kubernetes, Istio, and more. Attendees can expect to walk away with fresh ideas about how to achieve fine-grained control throughout their systems.

More from KubeCon Europe 2018

Open in the index →
  1. The Route To Rootless ContainersEd King, Pivotal & Julz Friedman, IBM 2018-05-02
  2. Securing your Kubernetes Delivery Pipelines with Notary and TUFLiam White & Michael Hough, IBM 2018-05-02
  3. Improving your Kubernetes Workload Security with Hardware VirtualizationFabian Deutsch, Red Hat & Samuel Ortiz, Intel 2018-05-02
  4. Establishing Image Provenance and Security in KubernetesAdrian Mouat, Container Solutions 2018-05-02
  5. Completely Securing the Software Supply Chain using Grafeas + in-totoLukas Puehringer, NYU & Wendy Dembowski, Google 2018-05-02
  6. No video Cloud Native Identity ManagementAndreas Zitzelsberger, QAware GmbH & Andrew Jessup, Scytale Inc. 2018-05-02
  7. Good Enough for the Finance Industry: Achieving High Security at Scale with Microservices in KubernetesZachary Arnold & Austin Adams, Ygrene Energy Fund 2018-05-03
  8. Entitlements: Understandable Container Security ControlsJustin Cormack & Nassim Eddequiouaq, Docker 2018-05-03
  9. Container Isolation at Scale (Introducing gVisor)Dawn Chen & Zhengyu He, Google 2018-05-03
  10. Case Study: How Containers Makes Security and Compliance Instantly EasierJohn Morello, Twistlock 2018-05-03
  11. Applying Least Privileges through Kubernetes Admission ControllersBenjy Portnoy, Aqua Security 2018-05-03
  12. TL;DR NIST Container Security StandardsElsie Phillips, CoreOS 2018-05-04
  13. Secure PodsTim Allclair, Google 2018-05-04
  14. Multi-Tenancy in Kubernetes: Best Practices Today, and Future DirectionsDavid Oppenheimer, Google 2018-05-04
  15. Kubernetes Runtime Security: What Happens if a Container Goes Bad?Jen Tong & Maya Kaczorowski, Google 2018-05-04
  16. From Kubelet to Istio: Kubernetes Network Security DemystifiedAndrew Martin, ControlPlane 2018-05-04
  17. A Hacker's Guide to Kubernetes and the CloudRory McCune, NCC Group PLC 2018-05-04