UPDATED 22:40 EDT / SEPTEMBER 27 2018

CLOUD

Kubernetes 1.12 release introduces new security capabilities

One of the hottest open-source enterprise software projects got a major update today.

Kubernetes version 1.12, announced by the Cloud Native Computing Foundation, comes with a host of new features, including a new TLS Bootstrapping security capability that developers have been working to implement for the past two years.

Kubernetes releases are significant because the software is by far and away the most prominent orchestration tool for software containers, which have emerged as a popular tool for developers as they allow them to build applications that can run on any computing platform without changes. Orchestration tools such as Kubernetes are necessary because without them, container deployments are almost impossible to manage at scale.

Kubernetes 1.12 is the third major release this year, following earlier releases in June and March. The headline feature is TLS Bootstrapping, which is a security feature that allows Kubernetes’ nodes, called Kubelets, to request and obtain Transport Layer Security certificates to secure clusters. TLS certificates are cryptographic protocols designed to provide communications security over a computer network.

“Security is a cornerstone of what we aim to provide with Kubernetes,” Stephen Augustus, a Kubernetes project manager at CoreOS Inc., which was acquired by Red Hat Inc. earlier this year, said in a blog post. “Since Kubernetes 1.4, we’ve been working on a framework to provide cluster operators the ability to manage TLS assets for the Kubernetes control plane components and the kubelet.”

Other new stable features in the release include support for Microsoft Azure Virtual Machine sets, which enable users of Microsoft Corp.’s cloud platform to create and manage a group of identical, load-balanced virtual machines. The release also comes with new cluster autoscaling capabilities, which are now generally available.

Another new feature relates to Kubernetes’ Container Storage Interface, which is used to present storage resources to individual clusters. CSI now supports something called “topology awareness,” which enables it to understand where its available storage resources are located.

“Stateful workloads can now have a conceptual understanding of where storage resources live, whether it be a rack, datacenter, availability zone or region,” Augustus said.

“Kubernetes is winning and winning fast when it comes on containers for next generation applications,” said Holger Mueller, principal analyst and vice president at Constellation Research Inc. “This new release is likely going to accelerate that trend further, with better autoscaling and multi tenancy sticking out.. TLs support improvements will be welcomed by CxOs as well.”

Additional new features are detailed in Augustus’ blog post. Kubernetes 1.12 is available to download from GitHub now.

Image: Cloud Native Computing Foundation

A message from John Furrier, co-founder of SiliconANGLE:

Your vote of support is important to us and it helps us keep the content FREE.

One click below supports our mission to provide free, deep, and relevant content.  

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well” – Andy Jassy

THANK YOU