Tigera Upgrades Calico Security
Policy Recommender
December 20, 2022
Tigera
introduced several new capabilities that help reduce an application's attack
surface. These capabilities include security policy recommendations for
namespaces, FIPS compliance for use by federal agencies, and new and improved
dashboards for faster troubleshooting.
The Security Policy Recommender has long been a useful tool for security-focused
Calico users to identify and deploy granular network security policies for
improved security at the pod level. Policy development requires an advanced
understanding of microservices that are interacting with and depending on each
other, microservices with vulnerabilities, those that need to communicate
outside the cluster, and those that are accessing sensitive data. The Security
Policy Recommender empowers organizations that lack the expertise to build
granular policies by accounting for this information to help users avoid outages
and increased vulnerabilities during policy development.
The latest iteration of the Security Policy Recommender recommends policies at
the namespace level in addition to policies at the pod level. This benefits
users interested in multi-tenant architectures and workload isolation by
enabling them to implement microsegmentation without any detailed knowledge of
application-level changes. Overall, this update increases team productivity by
enabling users – no matter their expertise – to take advantage of automated
policies to improve the security posture of their Kubernetes clusters.
The
latest Calico update also enables users to become FIPS compliant, a standard
that is required of customers that serve federal agencies. To satisfy compliance
requirements and make the platform accessible to more users, Calico now offers a
FIPS-compliant installation/deployment mode so that customers can meet FedRAMP
requirements when using EKS or similar platforms for managed Kubernetes
services.
"These platform updates demonstrate Tigera's commitment to serving customers of
all sizes and needs," said Amit Gupta, Chief Product Officer, Tigera. "Instead
of building a tool for the largest share of the market, our team is constantly
iterating to ensure the platform is accessible, useful, and responsive to
everyone from small teams to large enterprises. Security and compliance are
critical considerations for organizations, and we look forward to seeing our
customers put these new capabilities to use in pursuit of more resilient and
compliant architectures."