本文从云原生架构出发,简要说明云原生的发展现状及其带来的安全挑战。为了应对这些安全挑战,参考Gartner和信通院的整体安全框架,结合国内需求,提出了安全框架的设计思路。据此思路,介绍了云原生全生命周期的安全防护能力,包括云基础设施安全、制品安全、运行时安全等方面内容,进而提出了一体化安全运营平台的建设运营方案。最后,简要介绍了一个实际部署的应用案例。
Beginning with cloud-native architecture,this article provides a brief overview of the current development status of cloud-native technology and the security challenges it presents. To address these security challenges,we have drawn from the comprehensive security frameworks developed by Gartner and the Institute of Information and Communications Technology,adapting them to domestic requirements,and proposed our design concepts for a security framework. Following this approach,we present an introduction to the security protection capabilities of cloud-native technology throughout its entire lifecycle. This includes aspects such as cloud infrastructure security,product security,runtime security,and others. Additionally,we propose a plan for constructing and operating an integrated security operation platform. Finally,we provide a brief overview of a practical deployment application case.