-

Trousseau Open Source Project Made Available to Add Security in Kubernetes

Universal way to manage secrets brings simplicity to implementations

LONDON--(BUSINESS WIRE)--Today, managing secrets to protect access to sensitive data in Kubernetes is complicated. It adds lots of components which are troublesome for security professionals. As a result, this security layer in Kubernetes is not optimal.

This changes with Trousseau’s open source project software, available today. Secrets management can now be added to Kubernetes along with support for any key management encryption, starting with HashiCorp Vault. The Trousseau open source software is available here on GitHub.

Romuald Vandepoel, principal cloud architect with Ondat and the project lead for Trousseau, said, “There have been previous projects that attempted to solve this problem, but they required adding lots of components. Naturally, security teams didn’t like that approach because it introduced additional complexity making security more difficult. Secrets management has always been one of the most difficult issues in Kubernetes and the Trousseau Vault integration provides the long-sought answer to that problem.“

Trousseau uses Kubernetes etcd to store API object definitions and states. The Kubernetes secrets are shipped into the etcd key-value store database using an in-flight envelope encryption scheme with a remote transit key saved in a KMS. Secrets protected and encrypted with Trousseau and its native Kubernetes integration can connect with a key management system to secure database credentials, a configuration file or TLS (Transport Layer Security) certificate that contains critical information and is easily accessible by an application using the standard Kubernetes API primitives.

"We're realizing two big benefits of Trousseau - First, simplicity as a plugin with the existing KMS, HashiCorp Vault, and second, integrating with GitOps workflows using the native Kubernetes API," said Bill Wong, CEO SunnyVision Limited. "It's provided us with the added security we need with out disruption."

With Trousseau, any user/workload can leverage the native Kubernetes way to store and access secrets in a safe way by plugging into any KMS provider, like Hashicorp Vault (Community and Enterprise editions), using the Kubernetes KMS provider framework. No additional changes or new skills are required. It’s also possible to transition among Kubernetes platforms using the consistent Kubernetes API.

Trousseau is currently being rolled out in a production customer implementation on Suse Rancher Kubernetes Engine 2 leveraging Ondat as the data management platform, along with Hashicorp Vault.

“This lack of a standardized approach to secrets management in Kubernetes has been detriment to security, and the complexity has been an impediment to adoption in certain cases,” said Asvin Ramesh, Senior Director, Alliances, Hashicorp. “We’re excited to support the Trousseau Vault open-source initiative which tackles this problem by delivering a new level of simplicity for Kubernetes users, along with better security protection.”

For more information, read How to keep a secret secret within Kubernetes, and join the Data on Kubernetes Meetup Unravel the Key to Kubernetes Secrets workshop on February 16.

About the Trousseau Project
Conceived in November 2020, the "why" behind Trousseau was presented at FOSDEM early in 2021, and the first open-source software made available in December. It provides native Kubernetes secrets management for controlled access to sensitive data that simplifies and brings better security to Kubernetes.

About Ondat
Ondat is the Kubernetes-native platform for running stateful applications, anywhere, at scale. Ondat delivers persistent storage directly onto any Kubernetes cluster for running business-critical, stateful applications safely across any public, private and hybrid clouds. For development, DevOps professionals and technology executives, it provides an agnostic platform to run any data service anywhere while ensuring industry-leading levels of application performance, high availability and security.

Contacts

Media
Joe Eckert for Ondat
jeckert@eckertcomms.com

Ondat


Release Summary
Trousseau’s open source project software allows secrets management to be added to Kubernetes along with support for any key management encryption.
Release Versions

Contacts

Media
Joe Eckert for Ondat
jeckert@eckertcomms.com

More News From Ondat

Ondat 2.8 Arrives in GA with Increased Support for Stateful Workloads in Kubernetes

LONDON--(BUSINESS WIRE)--Ondat, the leading Kubernetes-native data platform provider, today released into general availability version 2.8 of its Ondat platform for stateful workloads in Kubernetes. The new version brings significant changes that open up the option of running a robust ETCD setup within production clusters, removing the need for external service setup. This change reduces operational overhead and cost for production users. Key enhancements in v2.8 include: Snapshots provide addi...

Open Source Advocate Alex Jones Joins Ondat Advisory Board

LONDON--(BUSINESS WIRE)--Alex Jones has been named to the advisory board of Ondat, the leading Kubernetes-native data platform provider. He serves as Kubernetes Engineering Director at Canonical and contributes to the CNCF TAG App Delivery as Tech Lead. He has invested more than a decade in engineering leadership roles at Microsoft, JPMorgan, American Express and British Sky Broadcasting. A frequent speaker, advisor and mentor, Alex is engaged in the cloud open source native technology communit...

Ondat Teams with SUSE to Protect Customers’ Sensitive Data with Enhanced Kubernetes Security

LONDON--(BUSINESS WIRE)--Ondat announced that it is teaming with SUSE to deliver secrets management to protect access to sensitive data for SunnyVision....
Back to Newsroom