aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
aster.cloud aster.cloud
  • /
  • Platforms
    • Public Cloud
    • On-Premise
    • Hybrid Cloud
    • Data
  • Architecture
    • Design
    • Solutions
    • Enterprise
  • Engineering
    • Automation
    • Software Engineering
    • Project Management
    • DevOps
  • Programming
    • Learning
  • Tools
  • About
  • Engineering

Introducing Custom Organization Policy For GKE To Harden Security

  • aster.cloud
  • October 19, 2022
  • 4 minute read

Compliance officers and platform engineering teams often find it challenging to ensure security, manage consistency, and oversee governance across multiple products, environments, and teams. Google Cloud’s Organization Policy Service can help tackle this challenge with a policy-based approach that simplifies policy administration across Google Cloud resources and projects.

We’re excited to announce the Preview release of Custom Organization Policy, and to showcase the integration with Google Kubernetes Engine (GKE). Custom organization policy for GKE can improve security and efficiency using guardrails you define tailored to your organization’s needs, and it’s offered to Google Cloud customers at no additional cost.


Partner with aster.cloud
for your next big idea.
Let us know here.



From our partners:

CITI.IO :: Business. Institutions. Society. Global Political Economy.
CYBERPOGO.COM :: For the Arts, Sciences, and Technology.
DADAHACKS.COM :: Parenting For The Rest Of Us.
ZEDISTA.COM :: Entertainment. Sports. Culture. Escape.
TAKUMAKU.COM :: For The Hearth And Home.
ASTER.CLOUD :: From The Cloud And Beyond.
LIWAIWAI.COM :: Intelligence, Inside and Outside.
GLOBALCLOUDPLATFORMS.COM :: For The World's Computing Needs.
FIREGULAMAN.COM :: For The Fire In The Belly Of The Coder.
ASTERCASTER.COM :: Supra Astra. Beyond The Stars.
BARTDAY.COM :: Prosperity For Everyone.

A policy is a statement of intent, such as “all clusters must be configured for auto-upgrade,” that gets implemented by the system. In our Organization Policy Service, a policy constraint is used to define the intent (auto-upgrade is enabled), and a policy is used to apply the constraint to a specific resource like a project or folder. Custom organization policy can extend the capability of our Organization Policy Service by helping you author your own custom constraints.

Let’s break down five ways Custom Organization Policy can help engineering organizations improve security and efficiency.

1. Consolidate and customize policy administration

 

Establishing and maintaining consistent configuration and security standards across multiple services, products, and teams can be challenging. Cloud solutions are the sum of many parts and securing them often requires deep collaboration across multiple teams and stakeholders.

Our Organization Policy Service helps consolidate and simplify policy administration, providing a single framework to efficiently manage policy enforcement across your organizational hierarchy. Organization Policy supports integration with GKE and other Google Cloud services using built-in policy constraints.

Read More  Data Movement For The Masses With Dataflow Templates

With the Preview of Custom Organization Policy for GKE, we’re excited to provide you the flexibility to define and enforce policies customized to your business and team needs.  Built-in and custom policy constraints are designed to be used together. Custom organization policies behave just like built-in organization policies and can be integrated into CI/CD workflows to deliver policy changes as code.

2. Grow beyond out-of-the-box security defaults

GKE can provide security “out of the box” by implementing security best practices as default values. For example, GKE uses shielded nodes, enables Cloud Logging, and disables the Kubernetes web dashboard by default. While our defaults are a solid baseline, compliance officers might have specific requirements when they attest security during audits. Your platform teams might also want to put guardrails in place to ensure these defaults and your organization’s own best practices are followed. Custom organization policy for GKE helps with both of these requirements.

At Google Cloud, we recommend managing security governance and compliance through policy. Policy establishes clear definitions and contracts across the multiple systems, processes, and teams involved. With a policy-based approach, you have additional opportunities to automate and integrate with other tools and processes to help reduce overhead and friction when tackling continuous compliance and security posture management.

The addition of Custom Organization Policy for GKE provides you with additional flexibility to define your security goals and engineering standards as policy, and to implement guardrails and enforcement at scale.

3. Powerful policy without add-ons

Custom Organization Policy for GKE comes ready-to-use for customers at no additional cost, and doesn’t require installation of additional cluster components. You simply define your custom policy constraints in a YAML file and then apply them to your Google Cloud resources using Cloud Shell or API.

Read More  FEDRAMP High Development in the Cloud: Code with Cloud Workstations

Because Organization Policy Service is built into GKE, it can reduce the burden on platform and security teams of managing the lifecycle of another add-on, and allow administrators to easily author new policy constraints.

You can also use Custom Organization Policy alongside popular third-party policy solutions such as Gatekeeper OPA or Kyverno. Custom Organization Policy enforces constraints on the GKE API (your clusters and node pools), while the other solutions can cover resources inside your Kubernetes clusters, such as your Deployments.

4. Cover niche exemptions to your rules

Wouldn’t it be nice if cloud security and governance was “all or nothing”? But like the saying goes, “every rule has an exception”. Security and platform teams often face the challenge of defining and implementing org-wide best practices while also supporting an exemption process for scenarios where those standards cannot be met.

Organization Policy provides tools for administrators to manage policy across different projects and resources using policy inheritance and the Organization Policy resource hierarchy. Admins can use the same framework to manage exemptions; it’s as easy as modifying a policy to include a new condition that exempts a specific resource. For example, to make an exemption for a specific GKE cluster, a new condition that identifies that cluster by tag can be added to the organization policy.

 

5. Drive efficiency through consistency

Engineering organizations are increasingly looking to policy solutions to codify engineering standards, implement guardrails for developers, and integrate continuous compliance and security upstream in the development process using automation.

Custom Organization Policy for GKE provides your organization a simple way to help define and enforce engineering standards for GKE clusters and node pools. The structured, policy-focused approach means that each constraint and policy can be consistent in syntax and readability. This feature can drastically reduce developer onboarding and learning times, and can minimize the need to maintain documentation that defines engineering guidelines and how to audit and enforce them.

Read More  Announcing Apache Iceberg Support For BigLake

Engineering standards and guardrails are integral to establishing security culture, driving development efficiency, and reducing friction in cross-team collaboration. Policy provides a clear and consistent representation of these standards, and the ability to audit and enforce them.

Get started today

The preview of Custom Organization Policy for GKE is a simple way to introduce flexible and powerful policy into your organization’s toolkit, and is built-in and ready to use at no additional cost. Whether it’s improving security, ensuring compliance, or implementing engineering standards, Custom Organization Policy can help.

Looking for a few examples to get started? Check out the examples on the Custom Organization Policy for GKE documentation. Want to know more about building security guardrails for developers on Google Cloud? Give this blog post a read.

 

 

By: Daniel L’Hommedieu (Product Manager)
Source: Google Cloud Blog


For enquiries, product placements, sponsorships, and collaborations, connect with us at [email protected]. We'd love to hear from you!

Our humans need coffee too! Your support is highly appreciated, thank you!

aster.cloud

Related Topics
  • GKE
  • Google Cloud
  • Google Kubernetes Engine
  • Security
You May Also Like
View Post
  • Engineering
  • Technology

Guide: Our top four AI Hypercomputer use cases, reference architectures and tutorials

  • March 9, 2025
View Post
  • Computing
  • Engineering

Why a decades old architecture decision is impeding the power of AI computing

  • February 19, 2025
View Post
  • Engineering
  • Software Engineering

This Month in Julia World

  • January 17, 2025
View Post
  • Engineering
  • Software Engineering

Google Summer of Code 2025 is here!

  • January 17, 2025
View Post
  • Data
  • Engineering

Hiding in Plain Site: Attackers Sneaking Malware into Images on Websites

  • January 16, 2025
View Post
  • Computing
  • Design
  • Engineering
  • Technology

Here’s why it’s important to build long-term cryptographic resilience

  • December 24, 2024
IBM and Ferrari Premium Partner
View Post
  • Data
  • Engineering

IBM Selected as Official Fan Engagement and Data Analytics Partner for Scuderia Ferrari HP

  • November 7, 2024
View Post
  • Engineering

Transforming the Developer Experience for Every Engineering Role

  • July 14, 2024

Stay Connected!
LATEST
  • college-of-cardinals-2025 1
    The Definitive Who’s Who of the 2025 Papal Conclave
    • May 7, 2025
  • conclave-poster-black-smoke 2
    The World Is Revalidating Itself
    • May 6, 2025
  • 3
    Conclave: How A New Pope Is Chosen
    • April 25, 2025
  • Getting things done makes her feel amazing 4
    Nurturing Minds in the Digital Revolution
    • April 25, 2025
  • 5
    AI is automating our jobs – but values need to change if we are to be liberated by it
    • April 17, 2025
  • 6
    Canonical Releases Ubuntu 25.04 Plucky Puffin
    • April 17, 2025
  • 7
    United States Army Enterprise Cloud Management Agency Expands its Oracle Defense Cloud Services
    • April 15, 2025
  • 8
    Tokyo Electron and IBM Renew Collaboration for Advanced Semiconductor Technology
    • April 2, 2025
  • 9
    IBM Accelerates Momentum in the as a Service Space with Growing Portfolio of Tools Simplifying Infrastructure Management
    • March 27, 2025
  • 10
    Tariffs, Trump, and Other Things That Start With T – They’re Not The Problem, It’s How We Use Them
    • March 25, 2025
about
Hello World!

We are aster.cloud. We’re created by programmers for programmers.

Our site aims to provide guides, programming tips, reviews, and interesting materials for tech people and those who want to learn in general.

We would like to hear from you.

If you have any feedback, enquiries, or sponsorship request, kindly reach out to us at:

[email protected]
Most Popular
  • 1
    IBM contributes key open-source projects to Linux Foundation to advance AI community participation
    • March 22, 2025
  • 2
    Co-op mode: New partners driving the future of gaming with AI
    • March 22, 2025
  • 3
    Mitsubishi Motors Canada Launches AI-Powered “Intelligent Companion” to Transform the 2025 Outlander Buying Experience
    • March 10, 2025
  • PiPiPi 4
    The Unexpected Pi-Fect Deals This March 14
    • March 13, 2025
  • Nintendo Switch Deals on Amazon 5
    10 Physical Nintendo Switch Game Deals on MAR10 Day!
    • March 9, 2025
  • /
  • Technology
  • Tools
  • About
  • Contact Us

Input your search keywords and press Enter.