You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Since confidentiality is the main selling point of constellation,
are there already any plans to make this visible via something like
a Dashboard or analyzing script showing the state of confidentiality?
depending on
Constellations version
Config
Hardware type
supported hardware features (CPU/Platform)
Cloud providers features (subset of Hardware features)
kernel versions used
Firmware version (Patches)
...
This is not only about the current state but also to give concrete advice, how its possible to optimize confidentiality, e.g.
move to Azure
use instances with newer hardware gens
update Constellation
change config to
...
Would you be willing to implement this feature?
Yes, I could contribute this feature.
The text was updated successfully, but these errors were encountered:
Maybe this could be thought as tool not only running in constellation but also other standard kubernetes environments like other checks do (e.g. kubebench)
In this case it could give (in addition to core value) a great marketing tool, if the result of a scan is "there is only minor confidentiality, to optimize this you have to move to constellation" :-)
if not standalone / on the long run:
one idea could be, to add this kind of analysis to trivy security operator https://github.com/aquasecurity/trivy-operator which e.g. includes also kubebench
Hey,
thank you for the suggestion.
Currently we include large parts of the information you are looking for in our attestation statements. You can learn about what specifically is included in our attestation docs. The Runtime measurements section will be of particular interest to you I assume.
The evidence of the attestation can always be viewed using the verify command. And the underlying code that gathers the evidence can be found here.
So in case you want to take a swing at this we would be happy to support. The idea sounds very nice. Realistically it is not the highest priority in our backlog, right now.
Use case
making state of confidentiality really transparent / have a good chance to optimize it
inspired from
Describe your solution
Since confidentiality is the main selling point of constellation,
are there already any plans to make this visible via something like
a Dashboard or analyzing script showing the state of confidentiality?
depending on
This is not only about the current state but also to give concrete advice, how its possible to optimize confidentiality, e.g.
...
Would you be willing to implement this feature?
The text was updated successfully, but these errors were encountered: