Git Product home page Git Product logo

Comments (8)

izgeri avatar izgeri commented on May 22, 2024 1

Here are the slides I shared at the 2/22/19 meeting on Mapping the Security Landscape

from tag-security.

JustinCappos avatar JustinCappos commented on May 22, 2024 1

@lumjjb and I are still working on our version of this, but we're at a point where it makes sense to have CNCF help us mock up a small part of what the final product would look like.

We could either do this now for the small part we have done or could wait, depending on what others think makes sense...

from tag-security.

izgeri avatar izgeri commented on May 22, 2024

Noting that I spoke to Torin @ OPA today, and he noted that he thinks OPA will fit into both

  • Identity & Access Control - Access Controls
  • Service Access - Service admittance & admission controllers

We talked about some strategies we are considering for categorizing projects, and I asked him to think about security-related attributes that apply to OPA (even divorced from the landscape sub-categories) to help us figure out how we might map them onto the landscape. That is, we have a sense that they probably belong in the subcategories above, and if we know the project also has attributes X1, X2, and X3, it might give us a sense of how to map those attributes into those subcategories in a way that other projects can also use, or it may highlight for us gaps in our current subcategory definitions.

Also, we are probably due for a brainstorm session on this - I will raise that at the next meeting.

from tag-security.

ultrasaurus avatar ultrasaurus commented on May 22, 2024

talked to @JustinCappos who has some ideas about how to better articulate the stages of cloud native tech to divide up the space... I think this is consistent with what @izgeri and I talked about when we reviewed the PR, but definitely needs a bit more elaboration to be sure.

In any case, I agree that as written the "Identity & Access Control" section isn't clear and could be interpreted as for every project, since every project at minimum needs its own access control.

from tag-security.

ultrasaurus avatar ultrasaurus commented on May 22, 2024

Recently telling someone how we arrived at target audience of deciders for whitepaper #138 which came from the discussion of the landscape and categories, where the group felt that landscape and security overview whitepaper (#138) would have the same target audience.

@izgeri helped find discussion in SAFE meeting notes 2/22/19

from tag-security.

lumjjb avatar lumjjb commented on May 22, 2024

Created issue for work @JustinCappos mentioned, and linking it:

#348

from tag-security.

fkautz avatar fkautz commented on May 22, 2024

Would it make sense to add other service meshes? Neither of the CNCF governed meshes (linkerd, Kuma) are listed but Istio is.

from tag-security.

lumjjb avatar lumjjb commented on May 22, 2024

Closing in favor of #348

from tag-security.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.