Alessia Moscuzza
Towards Automated Security Policy Management in Kubernetes.
Rel. Cataldo Basile, Francesco Settanni. Politecnico di Torino, Corso di laurea magistrale in Ingegneria Informatica (Computer Engineering), 2025
Abstract
Kubernetes network security is critical for protecting containerized applications, but by default, the platform provides no way to enforce security policies beyond basic NetworkPolicy resources with limited capabilities. Nowadays, there are different security tools to enforce network policies and among the others the main are Cilium, Calico, KubeArmor, and Tetragon. Each tool has its own policy specification language, creating a fragmented security environment. This forces organizations into vendor lock-in, makes migration between solutions difficult and expensive and prevents the adoption of the best security strategy that combines capabilities from different tools. Security engineers, or even worse developers, to whom security is often delegated to, are forced to learn multiple policy languages and manually translate them when changing tools.
This thesis addresses the interoperability challenge through an abstraction layer that split policy definitions from its tool-specific language
Relatori
Anno Accademico
Tipo di pubblicazione
Numero di pagine
Informazioni aggiuntive
Corso di laurea
Classe di laurea
URI
![]() |
Modifica (riservato agli operatori) |
