2022-01-21 08:02:07 -05:00
|
|
|
.. _index-security-84d0d8aa401b:
|
|
|
|
|
2020-08-31 11:01:56 -04:00
|
|
|
========
|
|
|
|
Security
|
|
|
|
========
|
|
|
|
|
2023-07-25 12:02:21 -03:00
|
|
|
.. _index-security-84d0d8aa401b-kubernetes:
|
|
|
|
|
2020-08-31 11:01:56 -04:00
|
|
|
----------
|
|
|
|
Kubernetes
|
|
|
|
----------
|
|
|
|
|
2021-09-17 11:11:45 -04:00
|
|
|
.. kub-begin
|
2020-08-31 11:01:56 -04:00
|
|
|
|
2021-09-17 11:11:45 -04:00
|
|
|
|prod-long| security encompasses a broad number of features.
|
2020-08-31 11:01:56 -04:00
|
|
|
|
|
|
|
.. _overview-of-starlingx-security-ul-ezc-k5f-p3b:
|
|
|
|
|
|
|
|
- |TLS| support on all external interfaces
|
|
|
|
|
|
|
|
- Kubernetes service accounts and |RBAC| policies for authentication and
|
|
|
|
authorization of Kubernetes API / CLI / GUI
|
|
|
|
|
|
|
|
- Encryption of Kubernetes Secret Data at Rest
|
|
|
|
|
|
|
|
- Keystone authentication and authorization of StarlingX API / CLI / GUI
|
|
|
|
|
2022-01-21 08:02:07 -05:00
|
|
|
- Barbican is used to securely store secrets such as |BMC| user passwords
|
2020-08-31 11:01:56 -04:00
|
|
|
|
|
|
|
- Networking policies / Firewalls on external APIs
|
|
|
|
|
|
|
|
- |UEFI| secureboot
|
|
|
|
|
|
|
|
- Signed software updates
|
|
|
|
|
2021-09-17 11:11:45 -04:00
|
|
|
.. kub-end
|
|
|
|
|
|
|
|
Contents:
|
|
|
|
---------
|
|
|
|
|
2020-08-31 11:01:56 -04:00
|
|
|
.. toctree::
|
|
|
|
:maxdepth: 2
|
|
|
|
|
2022-01-21 08:02:07 -05:00
|
|
|
kubernetes/index-security-kub-81153c1254c3
|
2021-03-18 08:11:53 -03:00
|
|
|
|
2023-07-25 12:02:21 -03:00
|
|
|
.. _index-security-84d0d8aa401b-openstack:
|
|
|
|
|
2021-03-18 08:11:53 -03:00
|
|
|
---------
|
|
|
|
OpenStack
|
|
|
|
---------
|
|
|
|
|
2021-09-17 11:11:45 -04:00
|
|
|
.. os-begin
|
|
|
|
|
|
|
|
.. os-end
|
2021-03-18 08:11:53 -03:00
|
|
|
|
|
|
|
.. toctree::
|
|
|
|
:maxdepth: 2
|
2021-04-19 00:22:38 -04:00
|
|
|
|
2022-01-21 08:02:07 -05:00
|
|
|
openstack/index-security-os-a2375141dcc2
|