Container orchestration engines like Swarm, Kubernetes and Mesos highlight the importance of network security that scales with growing deployments. With Cloud Native applications built by composing microservices, the ability to control traffic as it flows among these services becomes critical.
The Kubernetes Network SIG worked over last year to define Network Policy with the ability to control traffic among containerized services. At the same time, open source projects Kuryr and MidoNet have been advancing to achieve network security for containers in a simplified, distributed architecture. Removing architectural bottlenecks, Kuryr + MidoNet efficiently implement security policies through the hardened Neutron framework for use by containers in large scale environments. In this talk, we will discuss the latest updates of the Kubernetes Network SIG group, insert Neutron as a networking framework, and explore Kuryr and MidoNet networking solutions with advanced use cases.
The attendee will learn about Kubernetes Network Policy primitives as defined by the Kubernetes-SIG for basic network access control between pods. The attendee will learn how the Network Policy is implemented by the Kuryr project, which leverages Neutron abstractions to provide containers with networking. Last but not least, the attendee will learn how the open source MidoNet SDN solution supports network policies and the benefits that MidoNet brings to the Kubernetes container orchestration engine.