Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cloud
    • Cloud
    • Cybersecurity

    OpenStack Boosts Container Security With Kata Containers 1.0

    Written by

    Sean Michael Kerner
    Published May 22, 2018
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      VANCOUVER, British Columbia—The OpenStack Foundation announced on May 22 the Kata Containers 1.0 release which is designed to bolster container security.

      The Kata Containers project provides a virtualization isolation layer to help run multi-tenant container deployments in a more secure manner than running containers natively on bare-metal. The effort provides a micro-virtual machine (VM) layer that can run container workloads.

      “Containers use cGroups, namespaces and other features of the Linux kernel to enforce rules on what a container can and can’t do,” the OpenStack Foundation’s Anne Bertucio said during an analyst briefing at the OpenStack Summit. “While cGroups and namespaces are good, they only provide one level of isolation between workloads.”

      The Kata Containers project started in December 2017 as the first new standalone effort from the OpenStack Foundation that operates outside of the organization’s existing structure for the development of the OpenStack cloud platform. On May 21, the OpenStack Foundation announced its second standalone effort—with the Zuul continuous integration, continuous deployment (CI/CD) project.

      The Kata Containers project was started as a joint effort between Intel which had been working on its own “clear” container technology for isolation and Hyper.sh which had been working on the Run V container security technology. The Kata Containers 1.0 release represents the culmination of the effort to to turn the work of Intel and Hyper.sh into into a unified and stable codebase. Over the past six months, the Kata Containers project has also grown beyond its initial two supporters. The project now also benefits from the financial support of ARM, Canonical, Dell/EMC, Intel and Red Hat. Other vendors including Microsoft are also participating in the Kata Containers project at a technical level.

      Microsoft Software Engineer Jessie Frazelle is on the Kata Containers architecture committee and was on the OpenStack Summit keynote stage to talk briefly about why she is interested in the project. Frazelle said that she first saw a demontration of Intel’s clear containers in 2015 and was immediately sold on the idea.

      “With the merger of Run V, community help and cloud providers, it can only mean better innovation in this space,” Frazelle said. “I’m super excited for the future and what this means for container infrastructure overall.”

      Bertucio noted that with the Kata Containers 1.0 release, the project enables an Open Container Initiative (OCI) runtime and provides seamless integration with both the Kubernetes Container Runtime Interface (CRI) and Docker. Looking forward to future releases, Bertucio said that the project will aim to provide support for multiple hypervisors and will also seek enable support for accelerators, including GPUs in the future.

      Jonathan Bryce the Executive Director of the OpenStack Foundation commented during the analyst session that among the reasons why Intel was originally interested container security is because it maps to hardware security.

      “They (Intel) have virtualization extensions that go all the way down to the processor and allow you to do trusted computing,” Bryce said.

      As such, Bryce said that by tying into the silicon’s virtualization extensions, containers can be secure all the way down to the bare metal hardware. He added that AMD also has a secure memory capability that also can be enabled to work well with Kata Containers. Extending Kata Containers and hardware security elements also has cloud impact. Bryce said that Microsoft Azure for example is able to now benefit from Kata Container elements with the hardware security provided by silicon vendors, to provide additional isolation.

      “Security is all about having layers,” Bryce said.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×