Suture: Stitching Safety onto Kubernetes Operators

Suture: Stitching Safety onto Kubernetes Operators
复制标题

缝合:将安全性缝合到 Kubernetes Operator 上

DOI:
10.1145/3426746.3434055
复制
发表时间:
2020
期刊:
ACM
影响因子:
--
通讯作者:
Benson, Theophilus A.
Benson, Theophilus A.
中科院分区:
--
文献类型:
--
作者:
Mahajan, Akshat;Benson, Theophilus A.

文献摘要

被引文献

相似文献

Kubernetes Operator 允许应用程序的自定义自动化以与集群无关的方式与应用程序一起打包。这种独特的属性消除了对应用程序内部操作专业知识的需求——这种领域知识,编码一次,可以分发到任何环境——但需要信任操作员在整个集群上运行任意操作。人们对这种范例的安全性或可靠性影响知之甚少。我们展示了对 54 名 Kubernetes 开发人员的调查结果,以及对 19 个 Operator 存储库的 215 个功能请求的分析,展示了用户在 Operator 上遇到的不平凡的安全问题。我们进一步建议开发 Suture,这是一种访问控制机制,旨在防止操作员出现大多数此类安全问题。
Kubernetes operators allow custom automation for applications to be packaged with the application in a cluster-agnostic manner. This unique property eliminates the need for inhouse operational expertise with the application --- such domain knowledge, encoded once, can be distributed to any environment --- but requires trusting the operator to run arbitrary actions across an entire cluster. Little is known about the security or reliability implications of this paradigm. We present results from a survey of 54 Kubernetes developers and an analysis of 215 feature requests against 19 operator repositories demonstrating the ways users have experienced nontrivial safety issues with operators. We further propose the development of Suture, an access-control mechanism that seeks to prevent the majority of these safety issues with operators.