Alessia Moscuzza
Towards Automated Security Policy Management in Kubernetes.
Rel. Cataldo Basile, Francesco Settanni. Politecnico di Torino, Master of science program in Computer Engineering, 2025
Abstract
Kubernetes network security is critical for protecting containerized applications, but by default, the platform provides no way to enforce security policies beyond basic NetworkPolicy resources with limited capabilities. Nowadays, there are different security tools to enforce network policies and among the others the main are Cilium, Calico, KubeArmor, and Tetragon. Each tool has its own policy specification language, creating a fragmented security environment. This forces organizations into vendor lock-in, makes migration between solutions difficult and expensive and prevents the adoption of the best security strategy that combines capabilities from different tools. Security engineers, or even worse developers, to whom security is often delegated to, are forced to learn multiple policy languages and manually translate them when changing tools.
This thesis addresses the interoperability challenge through an abstraction layer that split policy definitions from its tool-specific language
Relators
Academic year
Publication type
Number of Pages
Additional Information
Course of studies
Classe di laurea
URI
![]() |
Modify record (reserved for operators) |
