Kubernetes Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/kubernetes/ Breaking news about the market for products, systems and services for the U.S. intelligence community Wed, 26 Nov 2025 15:04:02 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg Kubernetes Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/kubernetes/ 32 32 59882712 AccuKnox and Carahsoft collaborate https://intelligencecommunitynews.com/accuknox-and-carahsoft-collaborate/?utm_source=rss&utm_medium=rss&utm_campaign=accuknox-and-carahsoft-collaborate Wed, 26 Nov 2025 15:04:02 +0000 https://intelligencecommunitynews.com/?p=43268 On November 20, AccuKnox and Carahsoft Technology Corp. announced a strategic partnership. Under the agreement, Carahsoft will serve as AccuKnox’s Master...

The post AccuKnox and Carahsoft collaborate appeared first on Intelligence Community News.

]]>
On November 20, AccuKnox and Carahsoft Technology Corp. announced a strategic partnership. Under the agreement, Carahsoft will serve as AccuKnox’s Master Public Sector Reseller and Aggregator, making the company’s comprehensive Zero Trust Application, DevSecOps, Cloud and AI Security offerings for IT, OT, 5G, drones, satellites, Internet of Things (IoT) and tactical edge available to the public sector through Carahsoft’s reseller partners and NASA Solutions for Enterprise-Wide Procurement (SEWP) V, Information Technology Enterprise Solutions – Software 2 (ITES-SW2) and National Association of State Procurement Officials (NASPO) ValuePoint contracts.

“Zero Trust Security for Application, Cloud and AI is increasingly becoming imperative. AccuKnox provides government agencies with a platform that delivers Zero Trust Security by design,” said Bryan Maizlish, federal business leader at AccuKnox. “Our partnership with Carahsoft significantly expands our reach, enabling federal, state and local agencies and education entities to procure and deploy relevant, secure and mission-critical digital assets. We are pleased to jointly accelerate AccuKnox’s capabilities into our customer’s operational environments.”

AccuKnox is a Gen-AI powered Zero Trust Cloud Native Application Protection Platform (CNAPP) that provides comprehensive multicloud and on-premise security. The CNAPP platform secures modern, comprehensive, multilayer and system-of-system workloads and devices (Kubernetes, Containers, API, AI/LLM, Agentic AI, IoT/Edge, OT, satellite, drone and 5G) and traditional assets (Virtual Machines) across all public, private and air-gapped clouds.

Focusing on the support of critical Zero Trust and cybersecurity protection for the Golden Dome, AccuKnox unifies relevant cybersecurity compliance, Zero Trust and runtime security protection across space, land, air and sea. The platform provides a comprehensive and multilayered system of systems that is interoperable, integrated and multi-level security compliant, identifying non-compliance, areas of vulnerability and risk and observability of real-time attacks. AccuKnox isolates and shuts down areas compromised by a cybersecurity breach, while protecting the integrity of the Golden Dome through an on-premise, air-gapped solution.

“AccuKnox’s Zero Trust security platform is a critical addition to our technology portfolio,” said Natalie Gregory, vice president for enterprise open source and DevSecOps solutions at Carahsoft. “The comprehensive platform allows public sector agencies and entities to protect themselves against current and emerging threats, and zero-day attacks. AccuKnox provides continuous compliance, a mandatory capability in the current world of AI-powered attacks. We look forward to working with AccuKnox and our reseller partners to expand agencies’ access to this platform, including the Golden Dome, and help them implement Zero Trust Security for applications, cloud and AI, while maintaining operational efficiency and mission readiness.”

Source: Carahsoft

Don’t miss out — become a paid subscriber to IC News, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post AccuKnox and Carahsoft collaborate appeared first on Intelligence Community News.

]]>
43268
Speed. Security. Simplicity. Rancher Government Transforms Kubernetes Operations in Classified Environments https://intelligencecommunitynews.com/ic-insiders-speed-security-simplicity-rancher-government-transforms-kubernetes-operations-in-classified-environments/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-speed-security-simplicity-rancher-government-transforms-kubernetes-operations-in-classified-environments Wed, 12 Nov 2025 14:03:30 +0000 https://intelligencecommunitynews.com/?p=43158 From IC Insider Rancher Government Solutions With IC Cloud Support, Intelligence Community teams can now provision and manage clusters faster...

The post Speed. Security. Simplicity. Rancher Government Transforms Kubernetes Operations in Classified Environments appeared first on Intelligence Community News.

]]>
From IC Insider Rancher Government Solutions

With IC Cloud Support, Intelligence Community teams can now provision and manage clusters faster and more securely, simplifying operations across the most restricted networks.

For mission owners across the Intelligence Community, secure modernization has long meant trade-offs: classified environments often lag behind commercial clouds in automation, speed, and usability. Rancher Government Solutions (RGS) helps close that gap.

RGS, a leader in secure, enterprise-grade Kubernetes management for the U.S. Government, has announced the General Availability (GA) of IC Cloud Support. This breakthrough capability brings full provisioning and lifecycle management to classified cloud environments without requiring access keys, custom software development kits (SDKs), or manual workarounds.

“Our customers in classified environments deserve the same operational simplicity and resiliency they get in commercial cloud,” said Adam Toy, Chief Technology Officer at RGS. “With IC Cloud Support, RGS brings that consistency to the most secure environments in government.”

The Challenge: Managing Kubernetes Behind the Airgap

Organizations operating in airgapped or restricted AWS and Azure regions face a radically different landscape from commercial cloud users. These classified environments are completely isolated by design, with no internet connectivity, external endpoints, or public resource exchange.

As a result, provisioning or managing Kubernetes infrastructure required manual, highly constrained processes:

  • Physically moving software via burned discs or removable media into SCIFs
  • Operating without identity access management (IAM) keys or secrets, since credential creation is prohibited
  • Rewriting code to communicate with .gov API endpoints and custom certificate authorities
  • Relying on imported clusters that limited access to Day-2 operations like scaling, shell access, or certificate rotation

 

This fragmentation left DevSecOps teams balancing compliance with complexity—manually managing infrastructure that, in commercial settings, takes minutes.

From Technical Preview to Full Operational Capability

When RGS first announced IC Cloud Support as a technical preview in March 2025, it was clear the capability filled a critical operational gap. The preview demonstrated that by leveraging a differentiated Rancher Government build, users could provision clusters in classified AWS regions by simply toggling the new “Carbide Instance Credential” option—removing the need for manually managed keys and secrets.

Since then, RGS engineers have expanded the feature set and hardened the integration for General Availability. The result: full RKE2 and EKS provisioning, native classified API endpoint compatibility, and seamless Day-2 lifecycle management—all inside the familiar Rancher Manager interface.

How It Works: Secure Automation Without Keys or Custom Code

At the core of IC Cloud Support is a Kubernetes-native approach that replaces manual access management with secure automation.

When IC Cloud Support is enabled, Rancher Manager uses the EC2 instance’s own IAM role (rather than user-managed credentials) to authorize access. This is powered by the Carbide Instance Credential, a hardened mechanism unique to RGS that uses instance metadata services to assume cloud permissions automatically.

This eliminates the need for:

  • Handwritten SDKs or API scripts
  • Local key storage or secrets rotation
  • Custom certificate handling for classified domains

 

The outcome: a keyless, zero-trust-aligned provisioning workflow that meets the stringent security expectations of intelligence and defense networks.

Full Parity for Classified Cloud Operations

The General Availability release introduces a complete suite of enhancements designed for mission-critical continuity:

  • Native provisioning for RKE2 and EKS clusters in classified AWS regions
  • Instance-level authorization via Carbide Instance Credential
  • Compatibility with classified API endpoints and certificates
  • Expanded Day-2 operations including node scaling, certificate rotation, snapshot/restore, and encryption key rotation
  • UI and UX parity across AWS Commercial, GovCloud, and classified regions

 

Together, these improvements eliminate operational gaps between environments, giving intelligence agencies feature parity and user experience consistency across classification levels.

Why It Matters for the Intelligence Community

For operators inside the Intelligence Community, the implications are significant.
Classified cloud environments support some of the nation’s most sensitive workloads—mission systems that demand both speed and assurance. IC Cloud Support means these systems can now be provisioned, scaled, and secured with the same simplicity and confidence found in commercial deployments.

Benefits include:

  • Faster mission delivery: Full provisioning in minutes, not days
  • Reduced human error: Eliminates manual configuration and scripting
  • Operational continuity: Consistent Rancher UI across all classification levels
  • Accelerated ATO cycles: Built-in compliance and evidence generation
  • Improved security posture: No external keys or unmanaged secrets

 

This advancement directly supports the Intelligence Community’s goals of agile modernization, zero trust implementation, and mission-ready cloud operations.

Availability and Next Steps

IC Cloud Support is now available to all RGS customers through the Carbide Portal and Registry. After downloading the latest Rancher Government build for Rancher Manager, users can deploy directly in classified regions by toggling the Carbide Instance Credential option during cluster provisioning.

For more information or to schedule a technical consultation, contact info@ranchergovernment.com or visit us at ranchergovernment.com.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Speed. Security. Simplicity. Rancher Government Transforms Kubernetes Operations in Classified Environments appeared first on Intelligence Community News.

]]>
43158
Snowflake acquires Crunchy Data https://intelligencecommunitynews.com/snowflake-acquires-crunchy-data/?utm_source=rss&utm_medium=rss&utm_campaign=snowflake-acquires-crunchy-data Tue, 03 Jun 2025 15:04:42 +0000 https://intelligencecommunitynews.com/?p=41867 On June 2, Snowflake announced at its annual user conference, Snowflake Summit 2025, its intent to acquire Crunchy Data, a leading...

The post Snowflake acquires Crunchy Data appeared first on Intelligence Community News.

]]>
On June 2, Snowflake announced at its annual user conference, Snowflake Summit 2025, its intent to acquire Crunchy Data, a leading provider of trusted open source Postgres technology and products. This acquisition will bring Snowflake Postgres, the AI-ready, enterprise-grade and developer-friendly PostgreSQL database to the AI Data Cloud, enabling developers with the full power of Postgres while providing the uncompromising governance, security and operational standards essential for building and running mission-critical AI applications.

Organizations across industries increasingly require an enterprise-grade and secure Postgres solution with full Postgres compatibility for their production apps. Snowflake Postgres will bring Crunchy Data’s proven track record of enterprise readiness within FedRAMP compliant environments directly into Snowflake’s AI Data Cloud.

PostgreSQL continues to dominate as the most popular database amongst developers, with 49% of all developers reporting they use it. Snowflake Postgres significantly simplifies how developers build, deploy and scale production-ready AI agents and apps. It leverages Crunchy Data’s technology, which has been engineered not just for quick experimentation, but for the entire lifecycle of building, deploying and operating the most important enterprise workloads. Crunchy Data’s out-of-the-box access to essential performance metrics, built-in robust scaling capabilities and powerful interface help developers build amazing apps fast.

With Snowflake Postgres, customers and partners such as Blue Yonder and LandingAI, who currently leverage PostgreSQL to power their applications’ operational data, can ship faster, operate more efficiently and gain a competitive advantage in the rapidly evolving shift towards AI agents.

“Our vision is to deliver the world’s most trusted and comprehensive data and AI platform to our customers. Today’s announcement of our proposed acquisition of Crunchy Data represents another reason why Snowflake is the ultimate destination for all enterprise data and AI needs,” said Vivek Raghunathan, SVP of engineering at Snowflake. “We’re tackling a massive $350 billion market opportunity and a real need for our customers to bring Postgres to the Snowflake AI Data Cloud.”

“We built Crunchy Data with the vision to become a Postgres solution of choice for leading enterprise organizations. Our deep-rooted commitment to stringent security and comprehensive compliance has made us the trusted Postgres partner for organizations across regulated industries, including federal agencies, Fortune 500 financial institutions and high-scale SaaS companies,” said Paul Laurence, co-founder at Crunchy Data. “We’re excited to join forces with Snowflake to provide their customers who already rely on Postgres the ability to run mission-critical regulated workloads with increased confidence and security on the Snowflake platform.”

Source: Snowflake

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post Snowflake acquires Crunchy Data appeared first on Intelligence Community News.

]]>
41867
Rancher Government Solutions and Kasm Technologies partner https://intelligencecommunitynews.com/rancher-government-solutions-and-kasm-technologies-partner/?utm_source=rss&utm_medium=rss&utm_campaign=rancher-government-solutions-and-kasm-technologies-partner Wed, 07 May 2025 14:22:54 +0000 https://intelligencecommunitynews.com/?p=41651 On May 6, Rancher Government Solutions (RGS) announced a strategic partnership with Kasm Technologies, a pioneer in modern virtual and containerized desktop...

The post Rancher Government Solutions and Kasm Technologies partner appeared first on Intelligence Community News.

]]>
On May 6, Rancher Government Solutions (RGS) announced a strategic partnership with Kasm Technologies, a pioneer in modern virtual and containerized desktop infrastructure (VDI/CDI). Together, RGS and Kasm are delivering a cloud-native, Kubernetes-powered workspace solution purpose-built to meet the mission-critical demands of government and defense organizations.

This partnership brings together RGS’s industry-leading open-source Kubernetes stack with Kasm Workspaces’ web-native VDI/CDI platform — offering a scalable, secure, and cost-effective alternative to legacy hypervisor-based solutions like VMware and Citrix.

“Government agencies can no longer afford to rely on legacy VDI platforms that are costly, complex, and vulnerable,” said Ryan Lewis, CEO of Rancher Government Solutions. “Our partnership with Kasm Technologies provides a modern, cloud-native solution that delivers operational simplicity, zero-trust security, and true multi-cloud flexibility.”

The RGS-Kasm solution redefines VDI/CDI for government use-cases, empowering agencies to securely deliver virtual desktops and applications across on-premises, hybrid, cloud, and air-gapped environments — without endpoint agents or proprietary hardware requirements.

“Together, we are transforming workspace delivery for federal agencies,” said Justin Travis, CEO of Kasm Technologies. “By combining our web-native VDI platform with Rancher’s secure Kubernetes stack, we are enabling government organizations to operate with greater agility, security, and cost efficiency — wherever their mission takes them.”

Source: Rancher Government Solutions

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post Rancher Government Solutions and Kasm Technologies partner appeared first on Intelligence Community News.

]]>
41651
Rancher Government and Sequoia partner https://intelligencecommunitynews.com/rancher-government-and-sequoia-partner/?utm_source=rss&utm_medium=rss&utm_campaign=rancher-government-and-sequoia-partner Wed, 12 Feb 2025 16:28:35 +0000 https://intelligencecommunitynews.com/?p=40957 On February 11, Rancher Government Solutions (RGS) and Sequoia Holdings, LLC., a trusted expert in DevSecOps and secure workload migration, announced a...

The post Rancher Government and Sequoia partner appeared first on Intelligence Community News.

]]>
On February 11, Rancher Government Solutions (RGS) and Sequoia Holdings, LLC., a trusted expert in DevSecOps and secure workload migration, announced a strategic partnership to enhance software supply chain security, classified workload deployments, and Kubernetes management for the Department of Defense (DOD), Intelligence Community (IC), and federal civilian agencies.

This collaboration integrates Rancher Government Carbide, an end-to-end solution for zero-trust software supply chain security, with Sequoia’s Combine platform, a “digital twin” environment that enables secure and seamless software validation for high-side deployments. The partnership ensures that government agencies and ecosystem technology partners can develop, test, and optimize their applications in an unclassified environment before deploying into classified networks, reducing risk and enhancing mission readiness.

“Rancher Government Solutions is committed to providing government customers with secure, scalable Kubernetes environments that meet the highest security standards,” said Brandon Gulla, CTO of Rancher Government Solutions. “By combining our Kubernetes management and Carbide’s software supply chain security with Sequoia’s Combine platform, we’re enabling agencies to confidently deploy applications into classified environments while ensuring zero-trust protection from development to deployment.”

Sequoia’s Combine platform plays a critical role in overcoming the four major challenges of deploying workloads in classified environments including: Access Control and Identity Management, Service Parity and Endpoint Emulation, Air-Gapped Networking, and Secure Software Development.

“Sequoia Combine is an essential capability for agencies and partners moving workloads into classified environments,” said John Schnelle, Principal Solutions Architect at Sequoia. “By integrating Combine with RGS’s Kubernetes management and Carbide supply chain security, we’re providing a trusted, end-to-end solution that enables government customers to accelerate secure DevSecOps without risk or delay.”

This strategic partnership empowers government agencies, intelligence organizations, and ecosystem partners to confidently navigate the unique security challenges of classified DevSecOps while eliminating the risks of unvalidated software deployment.

Source: Rancher Government

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post Rancher Government and Sequoia partner appeared first on Intelligence Community News.

]]>
40957
Cubic DTECH Fusion eHPC achieves Red Hat certifications https://intelligencecommunitynews.com/cubic-dtech-fusion-ehpc-achieves-red-hat-certifications/?utm_source=rss&utm_medium=rss&utm_campaign=cubic-dtech-fusion-ehpc-achieves-red-hat-certifications Mon, 09 Sep 2024 12:23:35 +0000 https://intelligencecommunitynews.com/?p=39691 On September 5, Cubic Defense announced that DTECH Fusion Edge High-Performance Compute (eHPC) is now certified for use with Red...

The post Cubic DTECH Fusion eHPC achieves Red Hat certifications appeared first on Intelligence Community News.

]]>
On September 5, Cubic Defense announced that DTECH Fusion Edge High-Performance Compute (eHPC) is now certified for use with Red Hat Enterprise Linux 9.4, the world’s leading enterprise Linux platform, and Red Hat OpenShift, the industry’s leading hybrid cloud application platform powered by Kubernetes.

“The certification validates that Fusion eHPC can deliver supercharged hybrid cloud technologies to the tactical edge in a single-case solution,” said Anthony Verna, senior vice president and general manager of DTECH Mission Solutions. “Fusion eHPC supported on Red Hat Enterprise Linux 9.4 and Red Hat OpenShift streamlines how we provide complex data, artificial intelligence and machine learning capabilities at the speed of conflict.”

Utilizing Fusion eHPC’s powerful 64-core CPU, Nvidia GPU and huge user-accessible storage, customers are now empowered to turn data into decisions by training AI models and running AI-enabled applications throughout the mission chain—in the cloud and at the tactical edge.

Deployed by several allied forces, DTECH server modules have been certified for use with Red Hat Enterprise Linux for several years. The addition of the DTECH Fusion eHPC to the family of systems with market-leading performance means users can now deploy their data-rich AI and machine learning (ML) applications from the cloud to the mission edge, even in denied, disrupted, intermittent and limited (DDIL) environments, the company said.

Source: Cubic

IC News delivers the situational awareness you need to get ahead and stay ahead in the IC contracting space. Subscribe today for full access to 10,000+ articles, plus new articles each weekday.

The post Cubic DTECH Fusion eHPC achieves Red Hat certifications appeared first on Intelligence Community News.

]]>
39691
Automating Postgres Security Compliance and Data Assuredness in the Age of Kubernetes https://intelligencecommunitynews.com/ic-insiders-automating-postgres-security-compliance-and-data-assuredness-in-the-age-of-kubernetes/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-automating-postgres-security-compliance-and-data-assuredness-in-the-age-of-kubernetes Mon, 19 Aug 2024 14:32:43 +0000 https://intelligencecommunitynews.com/?p=39529 From IC Insider Crunchy Data By: Adam Timm Data is the crown jewel of any system and is the reason...

The post Automating Postgres Security Compliance and Data Assuredness in the Age of Kubernetes appeared first on Intelligence Community News.

]]>
From IC Insider Crunchy Data

By: Adam Timm

Data is the crown jewel of any system and is the reason why the Authority To Operate (ATO) process is so thorough within the United States Department of Defense (DoD) / Intelligence Community (IC). It is the Authorizing Officials (AO)’s responsibility to ensure that the system is properly designed and configured to protect the data from unauthorized access and disclosure. Security Technical Implementation Guides (STIG) exist as resources for both system developers and AO’s to reference, but they are often not simple step-by-step instructions and can seem like they were written in foreign languages, especially when not specific to the applicable software. This is a major source of friction for ATO and slows program deployments. Add in the complexity of Kubernetes, and AO’s are quickly overwhelmed.

The number of Postgres deployments have grown dramatically due to its efficiency and performance, with Postgres being named the most popular database for developers for the second year in a row by Stack Overflow 2024 Developer Survey. However, Postgres is no stranger to complexity when it comes to configuring Postgres instances according to the STIG to meet the demands of an ATO. Crunchy Data has been working with the DoD / IC for over a decade to enable programs to confidently and securely deploy Postgres, from proof of concept to ATO, saving program engineering time and fielding mission systems more rapidly and securely.

The Crunchy Postgres STIG

The STIG is the configuration standards for DoD Information Assurance (IA) and IA-enabled devices/systems published by the United States Defense Information Systems Agency (DISA).

The Crunchy Postgres STIG translates these higher-level DoD security objectives into Postgres specific guidance. This removes ambiguity for both new, and experienced Postgres users, making compliance easier to achieve the first time.

The Crunchy Data PostgreSQL STIG covers 35 different standards with over 100 individual security controls, providing actionable guidance on the configuration of PostgreSQL to address requirements associated with:

  • Auditing
  • Logging
  • Data Encryption at Rest
  • Data Encryption Over the Wire
  • Access Controls
  • Administration
  • Authentication
  • Protecting against SQL Injection

 

Compliance Challenges in the Era of Containers

Containers and Kubernetes have facilitated modernization and enabled a number of new workflows. Crunchy Data provides leading tooling to bring Postgres to containerized and Kubernetes native workflows. However, security configuration and compliance can still be a manual, or customer process, thereby slowing down time to deployment in production. How do we align rapid deployments with rapid compliance?

The typical approach to security with containers is to ensure the container base image is “hardened” (i.e. free of CVE’s, proper settings in the OS, etc). This is a necessary, but not sufficient, first step in deploying container images generally, and containerized Postgres specifically. The challenge that is often initially overlooked is the number of security controls that need to be applied to the containerized STIG once the image is running. In particular, the Postgres STIG includes several controls that can only be applied to a running Postgres instance.

STIG Automation in Kubernetes

Container images deployed in a Kubernetes environment present the additional challenge in that Kubernetes is designed to be a stateless platform that will dynamically redeploy container images. While this approach has several benefits, the downside is that manual configuration of Postgres in Kubernetes is not particularly attractive as those manually applied configurations will be reset in connection with a redeployment.

Kubernetes fortunately provides the foundational automation framework that can be extended to support both the deployment and secure configuration of containerized database deployments.  Crunchy Postgres for Kubernetes extends Kubernetes through the use of its market-leading Kubernetes Operator for Postgres that customizes Kubernetes automation in order to support post installation security configurations through the use of a standard Kubernetes API – Custom Resource Definition (CRD).  Additionally, just as with other aspects of Postgres, you will want to monitor the configuration in operations to ensure there is no drift or unintended modifications to the security configuration.

Crunchy Postgres for Kubernetes addresses these specific challenges associated with applying Postgres STIG configuration in a containerized and Kubernetes environment by:

  • Providing secure Postgres Container Images as a Baseline. Crunchy Postgres and PostGIS container images provide the benefit of an actively maintained and “hardened” container image available through a variety of registries including the IronBank or deployed locally to program local registries.

 

  • Automating the Crunchy Postgres STIG Assessment. Crunchy Postgres for Kubernetes provides this Kubernetes native automation through an API that enables programs to perform an on-demand assessment of their Postgres cluster to observe the current status of the security configuration.

 

  • Applying Configuration of Crunchy Postgres STIG controls. Crunchy Postgres for Kubernetes enables users to apply the STIG configurations via manifest file. Crunchy Data provides a customizable default file with the recommended settings configured as well as supporting ‘justification’ materials that can be easily ingested into common STIG viewers and ATO authorization packages.

 

On average, this has saved Crunchy Data customers over 100 hours of engineering time and integrated with enterprise-continuous monitoring solutions for a holistic security view of their Postgres environments.

Beyond the STIG, Kubernetes-Native ATO Ready Postgres

Data security and assuredness goes beyond ensuring that Postgres is properly configured according to the STIG. Crunchy Postgres for Kubernetes provides Kubernetes-native automation and tooling to support the full spectrum of secure production Postgres deployment including:

  • High Availability
  • Disaster Recovery
  • Self Healing
  • Automated, Postgres aware backups
  • Monitoring
  • Ease of Scaling
  • Ease of upgrades

 

These aspects should be considered as foundational elements to any system; however they are often viewed as “too expensive” or the mission makes certain compromises because adding these features is viewed as too complicated. This is no longer the case, and programs should not accept excuses otherwise.

Benefits of Crunchy Postgres

Crunchy Postgres builds on the ‘community’ PostgreSQL database server maintained by the PostgreSQL Global Development Group to add extensions and utilities that are commonly required for production use cases such as High Availability, Disaster Recovery and Self-healing among others.

To ensure that Crunchy Postgres provides users with the most trusted distribution of production-ready PostgreSQL, addressing the range of potential security and potential requirements – from supply chain to disaster recovery – Crunchy Data builds, integrates and packages and certifies Crunchy Postgres the PostgreSQL database server with these essential open source components.  To meet the unique needs of the US DoD/IC, this trusted distribution is combined with Crunchy Data’s 24 x 7 x 365 expert Postgres support from US Based, US citizen engineers.

Community Postgres Crunchy Postgres
ACID Compliant Relational Database X X
Multi-Version Concurrency Control (MVCC) X X
Developer and Data Science Friendly functions X X
Numerous third party integrations X X
Certified Deployments on all major operating systems X X
Common Criteria EAL 2+ certificate X
Automated Backups X
Point in Time Recovery (Disaster Recovery) X
High Availability (automated failover) X
Managed, seamless version upgrades

 

X
24x7x365 support team X

 

See Crunchy Postgres for Kubernetes in Action

Crunchy Postgres for Kubernetes delivers an operationally proven, “ATO ready”, secure Postgres experience for Kubernetes, enabling organizations to streamline and standardize their approach to securely configuring Postgres in Kubernetes per the STIG. Check out our upcoming events for upcoming opportunities to see Crunchy Postgres for Kubernetes in action, or reach out to learn more about how Crunchy can help you with your ATO.

 

About Adam Timm:

Adam is the Field CTO-US Public Sector for Crunchy Data. He is an Air Force vet, former Intelligence Officer, and now an open source advocate. He has experience with Government Acquisitions, satellite and airborne Intelligence, Surveillance, and Reconnaissance systems, Digital Transformation initiatives, and now driving adoption of open-source software in the DoD and Federal Government. He currently lives in WI with his wife and four children.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

 

The post Automating Postgres Security Compliance and Data Assuredness in the Age of Kubernetes appeared first on Intelligence Community News.

]]>
39529
Rancher Government secures DoD ESI agreement https://intelligencecommunitynews.com/rancher-government-secures-dod-esi-agreement/?utm_source=rss&utm_medium=rss&utm_campaign=rancher-government-secures-dod-esi-agreement Tue, 16 Jul 2024 13:53:10 +0000 https://intelligencecommunitynews.com/?p=39241 On July 15, Rancher Government announced its inclusion as a provider in the Department of Defense’s (DoD) Enterprise Software Initiative (ESI) DevSecOps...

The post Rancher Government secures DoD ESI agreement appeared first on Intelligence Community News.

]]>
On July 15, Rancher Government announced its inclusion as a provider in the Department of Defense’s (DoD) Enterprise Software Initiative (ESI) DevSecOps Phase II SEWP Marketplace. This achievement marks a pivotal step forward in Rancher Government’s commitment to supporting the U.S. government’s IT modernization efforts, the company said.

The DoD ESI aims to streamline the acquisition process for software and services across the DoD, leading to significant cost savings and improved efficiency. Admittance into the ESI program is a validation of Rancher Government’s commitment to be a trusted partner to the DoD, delivering advanced infrastructure management solutions that meet their stringent compliance and security requirements.

“Being part of the ESI agreement allows us to further our mission of providing the DoD with powerful, flexible, and secure, cloud native Kubernetes and container solutions,” said Paul Smith, CEO of Rancher Government. “Our inclusion is not only a testament to the robustness of our offerings but also aligns with our strategic vision to support critical missions of the United States Government and Military.”

As an ESI SEWP Marketplace provider, Rancher Government will partner with five prime agreement holders to deliver on this vision. Those organizations include FCN IT, GovSmart, Thundercat Technologies, Carahsoft and DLT Solutions LLC.

“We are excited and honored to be given this opportunity to expand how we and our ecosystem partners support the DoD. At Rancher Government we believe that you must meet the customer at their mission and ESI enables us to do that more effectively when engagements move into the procurement phase,” said Dylan Miller, director of channels at Rancher Government. “And being SEWP based, the DevSecOps Phase II marketplace will provide an efficient, economical and familiar vehicle that will help our DoD customers accelerate the adoption and deployment of our cloud native technologies.”

Source: Rancher Government

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post Rancher Government secures DoD ESI agreement appeared first on Intelligence Community News.

]]>
39241
Rancher Government Solutions and Curtiss-Wright announce collaboration https://intelligencecommunitynews.com/rancher-government-solutions-and-curtiss-wright-announce-collaboration/?utm_source=rss&utm_medium=rss&utm_campaign=rancher-government-solutions-and-curtiss-wright-announce-collaboration Thu, 18 Apr 2024 12:19:07 +0000 https://intelligencecommunitynews.com/?p=38416 On April 17, Rancher Government Solutions (RGS), provider of Kubernetes and container management solutions to the U.S. government, announced a strategic...

The post Rancher Government Solutions and Curtiss-Wright announce collaboration appeared first on Intelligence Community News.

]]>
On April 17, Rancher Government Solutions (RGS), provider of Kubernetes and container management solutions to the U.S. government, announced a strategic alliance and reseller agreement with Curtiss-Wright’s Defense Solutions Division.

Working in collaboration, the two companies will bring Kubernetes to the tactical edge, extending the public, private, hybrid, and government cloud, from all leading cloud service providers, to disrupted, disconnected, intermittent and low-bandwidth (DDIL) environments while maintaining stringent U.S. government security regulations. This will, for the first time, provide warfighters at the edge with access to the enterprise-class cloud capabilities they have come to rely on, regardless of connectivity, and enable users to better manage critical workloads and more easily deploy applications from the cloud to the edge.

“Our warfighters have come to rely on cloud computing capabilities, but until now, connectivity issues have hindered their availability at the tactical edge. We are very excited to partner with Rancher Government Solutions to bring their secure enterprise-class cloud capabilities hosted on the PacStar 400-Series platform to the tactical edge for the first time,” said Brian Perry, senior vice president and general manager, Curtiss-Wright Defense Solutions Division. “We look forward to extending our relationship with Rancher Government Solutions to develop edge solutions for our customer base. Our plans include bringing their technology to additional Curtiss-Wright compute platforms, including the newly released size, weight, and power optimized PacStar 200-Series, the ultra-rugged Parvus DuraCOR product family and our broad range of 3U and 6U VPX form factor SOSA aligned solutions.”

“We are proud to be working with Curtiss-Wright to deliver transformational solutions focused on the U.S. government military and civilian use cases and tailored to the unique demands of the Tactical Edge,” said Ben Zifrony, VP of channels and alliances at Rancher Government Solutions. “Our combined solutions are not just about adapting to the edge but thriving in it, delivering a cloud-native platform that is secure, scalable, and sustainable, across Curtiss-Wright’s compute platforms and regardless of the operating environment.”

As a result of this collaboration, PacStar 400-Series tactical communications solutions, such as the PacStar 451 Server Module and PacStar MDC, will be able to host the Rancher Multi Cluster Manager (MCM) and Harvester hyper-converged infrastructure (HCI) technologies, to support both container and virtual machine workloads at the tactical edge.

Source: Rancher Government Solutions

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post Rancher Government Solutions and Curtiss-Wright announce collaboration appeared first on Intelligence Community News.

]]>
38416
Closing the air-gap: Advancing flexibility in analytic pipelines https://intelligencecommunitynews.com/ic-insiders-closing-the-air-gap-virtualizing-the-analytic-pipeline/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-closing-the-air-gap-virtualizing-the-analytic-pipeline Mon, 18 Mar 2024 13:38:06 +0000 https://intelligencecommunitynews.com/?p=38104 From IC Insider Red Hat Adopting an OSINT model, including the extended version, offers ways to extend and utilize commercial...

The post Closing the air-gap: Advancing flexibility in analytic pipelines appeared first on Intelligence Community News.

]]>
From IC Insider Red Hat

Adopting an OSINT model, including the extended version, offers ways to extend and utilize commercial analytic capabilities, albeit with limitations. Ideally, leveraging commercial capabilities without these constraints would allow the Intelligence Community (IC) to effectively tailor data processing and analytics to their missions.

Moving organic analytic tools outside the air-gap is currently risky. New technologies like confidential computing and AI/ML play a crucial role in enabling the IC to regain control over analytic processes previously restricted by air-gapped environments. Fundamentally, leveraging OSINT and existing commercial analytics tools goal is pushing traditionally air-gapped analytics into untrusted domains and relying on these new technologies to protect these analytics from being easily compromised.

Figure 1: If we could safely move production analytic tools outside the air-gap, we could leverage the economies, scale, and reach of commercial infrastructure providers.

When synthesized with the current air gapping method, several crucial approaches and technologies significantly enhance operational security objectives, such as:

Declarative systems

Declarative approaches allow us to state our intentions of how a system should behave – automation realizes these intentions. Directed at the broad domain of data management, we can apply declarative approaches to separate roles and functions, enforce discrete and differential access controls, lower insider risks, or remove human errors. Declarative IT is usually though of as a system administration or DevOps tool. Increasing use and adoption of declarative approaches for data science and machine learning operations (or MLOps) is opportunity to acquire these same advantages for analytics processes.

Figure 2: A data pipeline (image from Apache Nifi)

Fortunately, the focus of data model engineering today is on precisely this declarative approach – seen in tool emergence. For example, Apache NiFi and Airflow or Kubeflow’s Data Pipelines –  define abstract ‘data pipelines’ and ‘model pipelines’, as fundamental tools for the composition of the associated systems. Using these, data scientists can define, test, and refine their data management and ETL workflows against test data in isolated or clean room enclaves. When ready, encoded and parameterized controlled artifacts are handed these off to others for further refinement, deployment to other domains, or forking and reuse by others. The data and the analytical products are decoupled, remain in their domain, and don’t need to travel with the data or model itself.

Figure 3: Using declarative pipelines for cross-domain analytic workflows

Effectively using a declarative approach where information protections are paramount requires automation and strong governance. We expect the system to behave as our automation dictates or fail in environments we don’t control.

Confidential computing

Protect a workload from its surrounding infrastructure (and vice versa) with emerging technologies that provide confidentiality assurances for our workloads. While a rapidly developing area, it’s accessible today in commodity IT depending on our needs and goals. Fundamentally, all of these use hardware-assisted means like trusted execution environments (TEEs) to create enclaves with strengthened security postures. Sensitive data and computations from unauthorized access are protected, even by privileged software or administrators, encrypting data and processes while in use.

In particular, confidential containers, as embodied by the CNCF Confidential Containers (CoCo) project, employ cloud-native platforms for confidential computing technologies. Many data and machine learning declarative pipeline approaches use containers as the primary means to orchestrate their pipelined activities, gaining enormous mutual synergies.

Figure 4: How we can protect workloads using confidential computing

Confidential containers and TEEs extend the protections provided by basic virtualization through built-in encryption, keeping our data pipeline execution or AI/ML models protected until loaded by the hardware TEE for use. Relying on encryption and virtualization technologies today for many multi-domain protections, one primary concern is establishing the authenticity and integrity of the software, data, and other components using Zero Trust Architectures and careful design and planning of our roots of trust and attestations.

Virtualization

Virtualization underpins a lot of approaches to protecting data in multi-domain and cross-domain applications. Confidential containers are the next evolution, but virtualization already enjoys near-ubiquitous hardware support and is used to create trusted security boundaries. It is a fundamental technology and, indeed, is used to implement confidential computing environments today where the platform itself can be trusted. Fortunately, this is the case for many environments where physical access and security are robust or the compute platform is managed, governed, and protected from tampering via automated declarative processes. Trusted cloud service providers are examples of where sufficient guarantees may be available. We can use hardware, software, and platform attestations to assert some assurances that we are operating on platforms that can be trusted in these fashions.

AI/ML

The properties of AI/ML models that make them challenging to trust can also aid in providing additional protections as we move analytics into other domains:  AI/ML should be the analytic approach of choice for this reason. First and foremost, AI/ML models inherently obfuscate the data contained within and the details of the flow of information within the models themselves. Still, inherent obfuscation must be tested and validated within the development and test environments to examine and probe for information leakage from the model. Tailored training incorporated into the declarative data and machine learning pipelines using automation and declarative policies validates their use when deployed to production.

AI/ML models must also be attached to various other objects, such as object or data embedding maps, and metadata to make them useful, and this is an opportunity to mutate or shard the models and add additional obfuscation. Sharding a model and separating key subparts (eg, a layer in a NN, a weight vector, shape, or other metadata parameters) lowers risk of compromise and impact if compromised. Layered declarative workflow constructs and confidential computing environments can further support this process of obfuscation and reconstruction. Confidential computing for AI/ML models, often a critical point of tradecraft, is also an excellent example of how we can protect these specific workloads using this technology.

Attestations, Blockchains, and distributed transactions

Regardless of the mix of tools discussed here, implementations all rely on the capability assertions and assurances provided by involved components. Confidential computing, whether via Kata containers or podman/libkrun relies on examining and validating the attestations provided. Complex provisioning and orchestration requires specialized platform components – attestations of the platform itself, anchored by hardware roots of trust anchored in the hardware. For example, keys and certificates must be loaded into the bootstrap process, the platform attestations verified, and the TEE initialized with the user data – for each use in a data analytics or model pipeline.

Figure 5: Managing attestation and the supporting keys and certificates in a confidential computing environment; extending this to data and model pipelines will require governance over distributed execution contexts and trust models

Today, PKI and traditional cryptographic signing and certificates are the model: critical assets we must control and protect carefully. As pipeline automation is applied for the critical management processes here, trust passes up and cannot be pre-built into the confidential computing paradigm. But hardware trust provided by Secure Boot, augmented with Policy-Based Decryption such as Network-Bound Disk Encryption, aids in this process. But future tools based on transparency logs like Google’s Trillian or SigStore may provide ways to distribute the trust process.

By embracing these technologies and approaches, the IC can achieve economies of scale, enhanced access, and improved security without compromising operational objectives. This strategic integration of advanced technologies mitigates risks associated with moving analytic processes outside air-gapped environments and enables organizations to realize their operational goals effectively and securely.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

 

The post Closing the air-gap: Advancing flexibility in analytic pipelines appeared first on Intelligence Community News.

]]>
38104