-

Ondat Teams with SUSE to Protect Customers’ Sensitive Data with Enhanced Kubernetes Security

SunnyVision obtains “secrets management” support from new open source Trousseau software

LONDON--(BUSINESS WIRE)--Ondat, the leading Kubernetes-native data platform provider, today announced it is teaming with SUSE, a global leader in innovative, reliable and secure enterprise-grade open source solutions, to deliver management of digital authentication credentials (secrets management) in Kubernetes to protect access to sensitive data for SunnyVision, a data center infrastructure service provider. This comes just after the release of Ondat’s Trousseau open source project in February.

Previously, secrets management in Kubernetes was complicated and added lots of components – anathema for security professionals. The Trousseau open source project addresses these issues, leading Ondat and SUSE to team up to provide this enhanced security for their customer, SunnyVision.

With SUSE Rancher and built-in Trousseau, SunnyVision can now leverage the native Kubernetes way to store and access secrets in a safe way by plugging into Hashicorp Vault using the Kubernetes KMS provider framework. No additional changes or new skills are required.

“Segregation of the encryption keys in our multi-tenant environment means every data volume has its own key and has secure access protected from any of the other tenants,” said Bill Wong, CEO, SunnyVision. “Trousseau guarantees the security of keys, and without it this sort of secure data storage for containers would be very complex and near impossible.”

Andy King, partner solution architect at SUSE, said, “The Ondat data platform is used by SunnyVision as the basis for its database as a service (DBaaS) which is attractive to managed service provider (MSP) customers. MSPs are able to build services on the DBaaS to provide customized solutions to their customers. The integration with SUSE Rancher to easily consume Key Management Systems (KMS) addresses the critical need for protecting sensitive data in cloud-native solutions deployed in the Kubernetes ecosystem.”

Trousseau uses Kubernetes etcd to store API object definitions and states. The Kubernetes secrets are shipped into the etcd key-value store database using an in-flight envelope encryption scheme with a remote transit key saved in a KMS. Secrets protected and encrypted with Trousseau and its native Kubernetes integration can connect with a key management system to secure database credentials, a configuration file or TLS (Transport Layer Security) certificate that contains critical information and is easily accessible by an application using the standard Kubernetes API primitives.

“Secrets management has always been one of the most difficult issues in Kubernetes,” said Romuald Vandepoel, principal cloud architect with Ondat and the project lead for Trousseau. “We’re glad to see Trousseau applied to that long-time problem being deployed at major installations as part of SUSE Rancher.”

About the Trousseau Project
Conceived in November 2020, the "why" behind Trousseau was presented at FOSDEM early in 2021, and the first open-source software made available in December 2021. It provides native Kubernetes secrets management for controlled access to sensitive data that simplifies and brings better security to Kubernetes. Learn more here.

About Ondat
Ondat is the Kubernetes-native platform for running stateful applications, anywhere, at scale. Ondat delivers persistent storage directly onto any Kubernetes cluster for running business-critical, stateful applications safely across any public, private and hybrid clouds. For development, DevOps professionals and technology executives, it provides an agnostic platform to run any data service anywhere while ensuring industry-leading levels of application performance, high availability and security.

Contacts

Joe Eckert for Ondat
Eckert Communications
jeckert@eckertcomms.com

Ondat


Release Summary
Ondat announced that it is teaming with SUSE to deliver secrets management to protect access to sensitive data for SunnyVision.
Release Versions

Contacts

Joe Eckert for Ondat
Eckert Communications
jeckert@eckertcomms.com

More News From Ondat

Ondat 2.8 Arrives in GA with Increased Support for Stateful Workloads in Kubernetes

LONDON--(BUSINESS WIRE)--Ondat, the leading Kubernetes-native data platform provider, today released into general availability version 2.8 of its Ondat platform for stateful workloads in Kubernetes. The new version brings significant changes that open up the option of running a robust ETCD setup within production clusters, removing the need for external service setup. This change reduces operational overhead and cost for production users. Key enhancements in v2.8 include: Snapshots provide addi...

Open Source Advocate Alex Jones Joins Ondat Advisory Board

LONDON--(BUSINESS WIRE)--Alex Jones has been named to the advisory board of Ondat, the leading Kubernetes-native data platform provider. He serves as Kubernetes Engineering Director at Canonical and contributes to the CNCF TAG App Delivery as Tech Lead. He has invested more than a decade in engineering leadership roles at Microsoft, JPMorgan, American Express and British Sky Broadcasting. A frequent speaker, advisor and mentor, Alex is engaged in the cloud open source native technology communit...

Open Source Advocate Lisa-Marie Namphy Named Ondat Advisor

LONDON--(BUSINESS WIRE)--The leading Kubernetes-native data platform provider, Ondat, today announced Lisa-Marie Namphy has been named to the company’s advisory board....
Back to Newsroom