Styra Enhances DAS
April 21, 2020

Styra announced new enhancements to their Declarative Authorization Service (DAS), including support for Kubernetes mutating webhooks and new compliance pack for pod security policies.

Styra DAS, the company’s first commercial product, is a management plane that enables Developers and DevOps teams to operationalize OPA authorization policies. These new enhancements extend the Styra DAS security and compliance solution for Kubernetes, enabling DevOps to author, distribute, monitor, audit and perform impact analysis for OPA policy-as-code guardrails, with a consistent framework.

As enterprises move containerized/cloud-native applications into production, they must ensure that workloads are secure and compliant with relevant regulations before they reach runtime. This can require manual reviews and operational overhead, both of which can lead to operational errors, risk and interruptions that slow developer productivity. Styra mitigates these risks with guardrails that integrate with Kubernetes to allow only what’s right, minimizing human error and preventing non-compliant workloads from ever reaching production.

Adding support for Kubernetes mutating webhooks enables Styra policies to go beyond “allow or deny,” to automatically append, update or add relevant parameters to ensure workloads are compliant before they reach production. Support for these Admission Controllers means Styra DAS can automatically remediate problems that would otherwise result in blocked workloads and manual review. The new Pod security policies (PSP) pack extends the existing best practices and PCI DSS 3.2 policy packs, all of which eliminate the need to research, identify and implement baseline guardrails/policies for Kubernetes. With best-practice guardrails in place from the start, human error and missteps that delay projects, slow delivery and introduce risk are eliminated.

“As more organizations embrace the cloud, they also need to adopt a cloud-native authorization policy in order to mitigate security and compliance risk. Our mission now is the same as it has been since we launched OPA -- to provide organizations with the guardrails necessary to implement a consistent policy framework across the entire app development environment,” said Tim Hinrichs, co-founder and CTO of Styra. “These new enhancements to Styra DAS help our customers eliminate manual overhead, minimize risk and accelerate development timelines.”

- Mutating Webhooks: Taking full advantage of Kubernetes Admission Control APIs, support for Mutating Webhooks means that Styra DAS can automate compliance and minimize the need for human intervention. This streamlines delivery pipelines and lessens interrupts that can distract and slow DevOps teams. The ability to automatically modify non-compliant workloads before deployment means, for example, that workloads missing critical configuration like resource requirements, privilege controls, labels or network parameters will have those details added programmatically, based on specified policy. Mutating webhooks can also help ensure correct, consistent deployment. For example, Styra DAS can enforce policy that automatically adds an appropriate sidecar, such as a proxy, to each relevant workload to ensure service mesh or networking rules always have the necessary components to keep clusters running correctly.

- Pod Security Policies Packs: PSPs, which are native to Kubernetes, enable developers to control access to the host operating system. Acting as built-in baseline guardrails across clusters, PSPs allow developers to enforce run-time permissions for a container and permit actions on the kernel. While PSPs are valuable to managing security risk, the time and expertise needed to research, identify and manually implement them on each Kubernetes cluster can result in costly delays due to misconfigurations. With Styra support for PSPs, developers can build, save and distribute PSP policy in discrete “packs” to accelerate Kubernetes adoption, decrease time spent writing and configuring policies from scratch and reduce human error. Styra eases the process of authoring configurations and distribution across clusters, while also providing DevOps teams impact analysis, monitoring and auditing of results.

Automatic webhook mutating and PSP packs are available now to all Styra customers.

Share this

Industry News

October 29, 2020

Cisco announced new software-delivered solutions designed to simplify IT operations across on-premise data centers and multicloud environments.

October 29, 2020

Bugsnag announced availability of user stability analytics, which will help developers gain a clearer understanding of how application errors are impacting the user experience and other key performance indicators (KPIs) for the business, as well as offer insights on whether to fix bugs or build new features.

October 29, 2020

HAProxy Technologies announced an open-source release of a VMware Open Virtual Appliance (OVA) virtual machine image of the HAProxy load balancer for vSphere, which HAProxy Technologies will maintain on GitHub.

October 28, 2020

Progress announced a number of new innovations designed to facilitate adoption and at-scale deployment of Chef offerings for both new and experienced users of the DevSecOps portfolio.

October 28, 2020

StackRox announced the release of KubeLinter, its new open source static analysis tool to identify misconfigurations in Kubernetes deployments.

October 28, 2020

Vercel announced Next.js 10 featuring a number of new capabilities that accelerate frontend developers’ ability to enrich end users’ web experiences globally.

October 27, 2020

ThinkTank has released a suite of applications designed to keep distributed agile teams aligned and engaged, regardless of physical location.

October 27, 2020

Cloudify, a Service Orchestration and Automation Platform, announced its latest 5.1 product release which aims to take one step further to permanently remove silos and roadblocks that are consistently associated with migration to the public cloud.

October 27, 2020

WhiteSource announced its new native integration for Microsoft Azure DevOps services.

October 26, 2020

NetApp unveiled a new serverless and storageless solution for containers from Spot by NetApp, a new autonomous hybrid cloud volume platform, and cloud-based virtual desktop solutions.

October 26, 2020

GeneXus released GeneXus 17, a new version of its platform that empowers enterprises to create and evolve new applications at unprecedented speed.

October 26, 2020

Alcide announced the company’s security solutions are now integrated with AWS Security Hub, sending real-time threat intelligence and compliance information to Amazon Web Services (AWS) for easy consumption by Security and DevSecOps teams.

October 22, 2020

Puppet announced Puppet Comply, a new product built to work with Puppet Enterprise aimed at assessing, remediating, and enforcing infrastructure configuration compliance policies at scale across traditional and cloud environments.

October 22, 2020

Harness announced two new modules: Continuous Integration Enterprise and Continuous Features.

October 22, 2020

Render announced automatic preview environments which are essential for rapid and collaborative development of modern applications.