Kaspersky Container Security Agents
Kaspersky Container Security Agents (hereinafter also referred to as “agents”) are a solution component that runs as a containerized application and provides security on nodes in accordance with configured security policies, in particular:
- Runtime security of containers running on the nodes.
- Network interaction between pods and applications inside containers.
- Integration with the orchestration platform and flow of data necessary for analysis of the orchestrator configuration and its components.
- Startup of containers from trusted images to prevent unverified images from running.
Agents are installed on all nodes of clusters and all clusters that need protection. Kaspersky Container Security works with two types of agents: cluster protection agents (csp-kube-agent) and node protection agents (csp-node-agent). Together they form groups of agents. A separate group of agents is created for each cluster. Multiple groups of agents can be created for one installation of the solution.
- Monitoring and control of container launches in accordance with security policies (Admission Control)
- Ensuring runtime security control of: processes, file operations, network activity; protection against file threats
- Visualization of cluster resources
The subscription includes a certificate for extended support — Premium.
With extended technical support, users can expect faster response and incident response, as well as additional contact slots.
How to activate Premium Support:
Link to activation
| Helm chart | Version | Pull-command | Documentation |
|---|---|---|---|
| cr.yandex/crplmv7sj9ccvn6e74ke/kaspersky/kcs/kcs-agents | 2.5.0-1 | Open |
| Docker image | Version | Pull-command |
|---|---|---|
| cr.yandex/crplmv7sj9ccvn6e74ke/kaspersky/kcs/node-agent1783591004085573370117913665135771724850050962315 | v2.5.0 | |
| cr.yandex/crplmv7sj9ccvn6e74ke/kaspersky/kcs/kube-agent1783591004085573370117913665135771724850050962315 | v2.5.0 |