Aqua Security for PCF (Beta)

WARNING: The Aqua Security for Pivotal Cloud Foundry (PCF) tile is currently in beta and is intended for evaluation and test purposes only. Do not use this product in a PCF production environment.

This topic describes the Aqua Security for PCF tile.

As a PCF operator, you can download and install the Aqua Security for PCF tile to deploy the Aqua Command Center in your PCF environment, which security teams can then use to set policies that determine whether your PCF droplets meet your organization’s security policies and may be deployed. As a developer, you can perform security scanning of your PCF applications at build time with immediate feedback about vulnerabilities and open source licenses in your code, all while complying with corporate GRC policies.

Overview

Aqua Security enables enterprises to secure their container and cloud-native applications from development to production, accelerating application deployment and bridging the gap between DevOps and IT security. Aqua’s Container Security Platform provides full visibility into container activity, allowing organizations to detect and prevent suspicious activity and attacks in real time. Integrated with container lifecycle and orchestration tools, the Aqua platform provides transparent, automated security while helping to enforce policy and simplify regulatory compliance.

Aqua Security for PCF enables customers to automatically scan droplets using the Aqua Decorator buildpack. It supports more than forty languages, including Java, Go, C++, Python, Ruby, NodeJS, and more, as well as static binaries. Aqua then either allows or prevents the droplets’ transition to the running environment, based on the scan results matched against your organization’s security policy. In addition, users can view detailed droplet risk information directly from within their preferred CI/CD tool (e.g. Concourse, Jenkins, TeamCity, etc.).

Key Features

With Aqua Security for PCF, you can benefit from these capabilities:

  • Scan droplets for known vulnerabilities based on data from multiple resource feeds (public CVEs, vendor-issued, proprietary vulnerability data streams, and malware)
  • Block unauthorized droplets based on droplet assurance policies, for example:
    • Stop unknown droplets
    • Stop droplets by CVEs and score
    • Detect and stop droplets with hardcoded secrets
  • Add custom compliance checks (bash, OPAL, and powershell-based)
  • View actionable mitigation information on how to mitigate detected vulnerabilities
  • Gain visibility into droplet vulnerabilities directly from CI tools (e.g. Concourse, Jenkins, TeamCity, Bamboo, Microsoft VSTS, etc.) and Aqua dashboard
  • Scan docker registries to identify unregistered containers

Product Snapshot

Note: As of PCF v2.0, Elastic Runtime is renamed Pivotal Application Service (PAS).

The following table provides version and version-support information about Aqua Security.

Element Details
Tile version version 0.8.9
Release date May 24, 2018
Software component version version 0.8.9
Compatible Ops Manager version(s) v1.11.x, v1.12.x, v2.0.x, and v2.1.x
Compatible Pivotal Application Service version(s) v1.11.x, v1.12.x, v2.0.x, and v2.1.x
IaaS support All platforms

Note: Upgrades from Aqua Security for PCF v0.8.1 or v0.8.7 to v0.8.9 are not supported. If you previously installed Aqua Security for PCF v0.8.7 or v0.8.1, uninstall it and install the latest version.

Requirements

Aqua Security for PCF has the following requirements: A purchased or thirty-day trial license provided by Aqua Security. You can request a trial license here or by emailing Aqua Security Sales.

Feedback

If you have a feature request, questions, or information about a bug, please email Pivotal Cloud Foundry Feedback list or send an email toAqua Security Support.

Troubleshooting

For help with troubleshooting this product, contact Aqua Security Support

Create a pull request or raise an issue on the source for this page in GitHub