Giulio Brazzo
Securing the computing continuum with fine-grained automatic network policies.
Rel. Fulvio Giovanni Ottavio Risso, Stefano Galantino. Politecnico di Torino, Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering), 2025
|
Preview |
PDF (Tesi_di_laurea)
- Tesi
Licenza: Creative Commons Attribution Non-commercial No Derivatives. Download (4MB) | Preview |
Abstract
The increasing adoption of the computing continuum, where applications span across cloud, edge, and on-premise infrastructures, has introduced new challenges in securing network communications. In such heterogeneous and dynamic environments, Kubernetes has emerged as the standard platform for orchestrating containerized workloads. However, its native networking model and built-in NetworkPolicies are often insufficient to guarantee fine-grained and adaptive traffic control, especially in multi-cluster scenarios. This thesis investigates how to achieve precise and automated network isolation within Kubernetes-based multi-cluster topologies, with a focus on deployments extended through Liqo, an open-source framework for transparent multi-cluster resource sharing. The proposed solution introduces multiple Kubernetes controllers capable of observing shared resources between different clusters, and dynamically generate security policies mapped to low-level nftables firewall rules or through Kubernetes Network Policies.
Specifically the aim is to define and enforce clear security boundaries around a Kubernetes cluster that is part of a multi-cluster topology
Tipo di pubblicazione
URI
![]() |
Modifica (riservato agli operatori) |
