Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cloud
    • Cloud
    • Cybersecurity

    Pivotal Cloud Foundry 2.4 Boosts Security With Compliance Scanner

    Written by

    Sean Michael Kerner
    Published December 20, 2018
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Pivotal is releasing version 2.4 of its Pivotal Cloud Foundry (PCF) platform on Dec. 20, providing organizations with a host of new capabilities to manage and deploy cloud-native applications.

      PCF is Pivotal’s commercial distribution, based on the open-source Cloud Foundry project, which provides platform-as-a-service (PaaS) capabilities for applications. In the PCF 2.4 update, Pivotal is adding zero downtime updates for application deployments, enabling organizations to roll out upgrades without downtime. PCF 2.4 also introduces a new compliance scanner in beta that will enable organizations to validate that the configuration of PCF deployments meets best practices.

      “We now have the ability to have zero downtime updates for the applications and the platform, and we’re doing that everywhere, whether you’re running vSphere or in OpenStack, GCP or AWS,” Richard Seroter, vice president of product at Pivotal, told eWEEK. “We’re highlighting the idea that you should be able to really go fast for all workloads on any infrastructure without sacrificing operability or security.”

      The PCF 2.4 release follows the PCF 2.3 update that was announced on Sept. 25 at Pivotal’s SpringOne Platform developer conference, alongside new updates for the Pivotal Container Service (PKS).

      How Zero Downtime Updates Work

      In the past, updating applications or an underlying platform typically involved some form of maintenance window where a system or platform became unavailable for a period of time. The promise of a zero downtime update is just that—even while an application or platform is being updated, users are not impacted.  

      So how does zero downtime actually work in production? Seroter explained that, for example, an organization could deploy an application (v1) with Cloud Foundry and then perhaps a second app (v2). After the v2 application is deployed, an administrator could then just simply switch the network route to enable the new version. The same basic method is now being scaled in an automated approach.

      “Let’s say I have five instances of my app and when I deploy the next version, under zero downtime deploy, as each instance of that app comes up in that same bucket, one of the old one comes out,” Seroter said. “I always have five running and I may be in a state where both versions are serving traffic, but at no point is there any disruption because in that same sort of app container, across all the different VMs [virtual machines] and Cloud Foundry, the application instances are swapping out for each other automatically.”

      Compliance

      PCF 2.4 also marks the beta debut of a new compliance scanner that will help organizations check the configuration and hardening posture of a PCF deployment. The scanner is based on the open Security Content Automation Protocol (SCAP) standard.

      “What the scanner does for the customers is basically ensure that the configuration of the OS matches the best practice recommendations for a cloud-native deployment,” John Field, security architect at Pivotal, told eWEEK.

      PCF relies on the open-source Ubuntu Linux operating system as the core. Field commented that deploying Ubuntu as a stand-alone server is somewhat different from the configuration required for a cloud-native deployment, where applications are brought up and down in a rapid manner.

      “What we’re looking to do is at scale is be able to manage the configuration scanning of the entire deployment and do that from the ops man [operations management] interface,” Field said. “So what really needs to happen here is that we need to run a scan of each of the VMs in the deployment and then do that to some configuration standard that is appropriate for cloud.”

      The initial beta release of the compliance scanner specifically looks at best practices for the operating system layer to meet compliance needs. Field said that the roadmap for the compliance feature is to continue to move up the stack in the future to enable other compliance needs for things that run on top of the OS. Field said that the compliance scanner effort comes from the Pivotal Compliance Innovation Team, which has a clear mandate for future development.

      “Our focus is to try to essentially change the way the world proves their compliance,” Field said. “That kind of goes hand in hand with the way we’re changing the way people build software.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.