Cryptography

Protecting Kubernetes Containers with nCipher HSMs

Protecting Kubernetes Containers with nCipher HSMs

Protecting Kubernetes Containers with nCipher HSMs

Containerisation has become a prevalent application deployment method across the IT sector. The number of containers in use has exploded, and to tame this growth various tools and frameworks have been developed. The most popular framework for container management is Kubernetes, which was developed and released as open source by Google. Many solutions build on and extend the Kubernetes framework to provide container deployment and management solutions.

Red Hat OpenShift is one of the most popular solutions built on Kubernetes. This provides everything needed to deliver containerised applications across hybrid-cloud deployments as required. Securing deployed applications and code running in containers is still vital, as it was in previous deployment models. Encryption, certificates, and PKI are still needed to establish security and chain-of-trust from applications to root certificate providers. nCipher nShield Hardware Security Modules (HSMs) are an industry-leading way to provide certificate cryptology you can trust. Now an Entrust company, nCipher have partnered with Red Hat for a decade to ensure their HSMs work flawlessly with Red Hat Enterprise Linux and other Red Hat products. Building on this decade's long partnership nCipher and Red Hat have certified nCipher nShield HSMs and nShield as a Service, together with the nShield Container Option Pack, to deliver enhanced security for containerised applications using cryptographic services. Applications requiring scalable, dynamic cryptography to generate keys or to sign and encrypt data can now use nShield HSMs to deliver these services to containerised applications running on Red Hat's OpenShift Kubernetes platform.

What is Containerisation?

Containerisation has become a core method of software packaging and deployment over the last few years. Containers are a method for packaging software and applications that grew out of virtualisation deployment methods. Everyone is probably familiar with the virtualisation model that uses a hypervisor running on top of an operating system, that allows multiple virtual machines to be deployed on the same underlying host hardware. In virtualisation each virtual machine (VM) has a separate copy of an operating system and any other software components installed that are needed for the applications running in the VM. Each VM is a separate entity that needs to be managed and updated.

Containerisation takes this to the next level. Containers are like VMs, but they don't need to have their own separate copy of an operating system installed. Instead, each container running on a host system shares the host operating system services via a Container Runtime. This is shown schematically in the diagram below (adapted from the Kubernetes website).

Protecting Kubernetes Containers with nCipher HSMs

As shown in the diagram, containers don't have their own separate operating system installed. As a result, they are more lightweight than traditional VMs while they also provide the abstraction benefits. Each container does have its own individual CPU allocation, memory, process space, and file system. So they are conceptually similar to VMs in that respect. The benefit of containers is that each one can be deployed and run unaltered on any target system such as Windows, Linux, Unix, macOS, and on various public cloud providers. This is very useful for DevOps and other development workflows. Development teams can write code and configure applications in containers on their local infrastructure. These can then be copied and deployed unaltered to production systems in local data centres or the cloud.

What is Kubernetes?

The lightweight nature and ease of use of containers means that they tend to proliferate in development and production systems. Some organisations can have thousands of containers spread across multiple private and public cloud locations. Like any other part of IT provision, when components increase in number there is an increase in the footprint that needs to be managed.

Kubernetes (pronounced "koo-ber-net-ees" and often abbreviated to 'k8s' or 'k-eights') is an open-source container management and orchestration toolset. It has seen rapid uptake, and there are many solutions on the market that deliver the core requirements specified by the Kubernetes framework, and then build on it to provide additional management and deployment functionality.

Red Hat OpenShift is 100% certified Kubernetes. It provides all of the components needed to run Kubernetes in production, including an underlying Linux platform, integrated networking, storage, monitoring, logging, installation, and upgrades. Red Hat OpenShift helps organisations transition to containers and Kubernetes.

How nCipher nShield HSMs Enhances the Security of Red Hat OpenShift

To provide robust security to applications running in containers, and managed on the Red Hat OpenShift Kubernetes platform, requires an integrated cryptographic solution. The nCipher nShield HSMs are specifically configured and certified to safeguard and manage cryptographic keys and processes within a Red Hat OpenShift Kubernetes deployment. They allow containerised applications to establish a root of trust for cryptographic operations.

The nShield security chain of trust is available for developers and operations teams building containerised application images, right through to the production system OpenShift Kubernetes deployment and management of multiple containers. As shown in the following diagram.

Protecting Kubernetes Containers with nCipher HSMs

For the running containers, the cryptographic reference that they can call upon for key management and cryptography can be on dedicated HSMs or via nShield as a Service in the cloud.

Contact Renaissance for More Info

Renaissance are proud partners with nCipher and their parent company Entrust. If you would like to find out more about the nCipher nShield HSMs and how they can integrate with the Red Hat OpenShift Kubernetes platform, then contact us. That also holds for any other cryptographic or security questions you may have about nCipher, Entrust, or other any other questions related to security.