Chapter 13. PaC and Infrastructure as a Service
Throughout this book, I have written about PaC solutions designed to prevent unwanted changes or behaviors in systems and artifacts. In Chapters 4 through 10, I showed you how different PaC solutions could be used to prevent unwanted changes from occurring in Kubernetes. Some of these same solutions could also audit, perform background scans, or execute CLI commands to interrogate existing Kubernetes resources.
In Chapters 11 and 12, I wrote about PaC solutions for IaC, how they detected issues—security and otherwise—and how they prevented the issues found in artifacts from propagating to IaaS resources. These PaC solutions could be used at the command line, included in automation, or be part of SaaS offerings.
PaC is routinely applied to existing IaaS resources as a means of detecting physical issues like drift and unwanted or disallowed resource configurations. Detection is not enough, though. PaC should react to prevent and even correct unwanted, potentially dangerous IaaS configurations. At a minimum, PaC should also notify users of situations found and actions taken. If PaC is not used to correct issues, then PaC should create findings that can be prioritized and remediated. In the case of IaaS in CSPs, PaC could create and radiate findings, using CSP-specific tools as well as external SIEM tools.
In this chapter, I will introduce two tools that are used to apply policies to existing IaaS resources to detect and potentially ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access