Abstract illustration featuring a large hexagon with a snowflake design in the center. The background shows a gradient sky, and the text reads, Upwind: Streamline Container Runtime Security with CRI-O Support.

Streamline Container Runtime Security with CRI-O Support

Denise Ashur February 28, 2024

Streamline Container Runtime Security with CRI-O Support

We are excited to announce support for CRI-O (Container Runtime Interface – Orchestrator).

CRI-O is an implementation of the Kubernetes Container Runtime Interface (CRI) to enable using Open Container Initiative (OCI) compatible runtimes, making integration between Kubernetes and container runtimes lightweight & seamless.

Upwind’s eBPF sensor will now support CRI-O users, in addition to our existing support of other container runtimes such as Containerd and Docker.

cri-o-map-1-1024x622

“Upwind’s support of Cri-o makes it easy for us to ensure that we have full visibility of our container environments and can protect them in real time. Leveraging Upwind helped us strengthen our cloud security and gives us end-to-end protection of all of our running workloads.”

-Dr. Yehuda Elmaliah, Co-founder & CEO, Cogniteam


This new capability allows you to receive runtime insights and protections for CRI-O Kubernetes environments including:

Using this new capability from Upwind to receive runtime protections and insights for Kubernetes environments with CRI-O runtimes and strengthen your overall infrastructure security. 

Contents

Further Reading

Let Me Speak to Your Manager (Account)

Let Me Speak to Your Manager (Account)

The management account is the most privileged account in any AWS Organization. It controls SCPs, creates and deletes member accounts, manages IAM Identity Center, and is itself exempt from SCPs. Getting its 12-digit account ID is the first step in targeting it. The documented way to get it is organizations:DescribeOrganization - but security-conscious environments restrict…
Configuration-Focus

Introducing the new Configurations experience in Upwind

Compliance should not be a fire drill! Ask a security team how audit season goes and you will often hear a version of the same story. Someone pulls a list of cloud accounts. Someone else exports findings into a spreadsheet that is already outdated by the time it is shared. Screenshots get pasted into a…
What You Could Build If IAM Let You

What You Could Build If IAM Let You: New Policies From Undocumented Condition Keys

In the previous post, we mapped 36 condition keys that the IAM engine evaluates but has never documented. The decomposition model, the service-specific resource identifiers, the organizational metadata - all of it sitting in the request context, invisible unless you probe for it. That post was about discovery. This one is about what you can…
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS