SUSE NeuVector makes your Kubernetes secure
Use Cases and Deployment Scope
We use SUSE NeuVector:
1) as a Kubernetes firewall to allow containers internal and external network connections which are necessary and block all other connections;
2) to scan our containers for known software vulnerabilities.
In the near future, we also plan to turn on command execution prevention to allow only whitelisted commands in certain containers.
Pros
- Scans containers software for known vulnerabilities
- Denies command execution in containers
- Prevents unwanted network connections from/to containers
Cons
- I like everything about NeuVector. They are on the right development path.
Most Important Features
- Ability to control network connections
- Container software vulnerability scanner
- Container registry vulnerability scanner
Return on Investment
- We went from being blind to what happens in the Kubernetes network to seeing everything and being able to control Kubernetes network communications.
- Now we are able to detect vulnerable containers faster.
Alternatives Considered
Sysdig Secure
Other Software Used
Oracle Linux, SUSE Rancher, Microsoft Visual Studio Code

