|
| 1 | +--- |
| 2 | + date: 2026-07-29 |
| 3 | + title: "Lights On! Real-Time Threat Response with Red Hat Advanced Cluster Security" |
| 4 | + summary: When network policies trap an attacker inside a container, what happens next? The ZTVP turns Red Hat Advanced Cluster Security into an active defense engine that detects anomalous behavior and terminates compromised pods in real time. |
| 5 | + author: Przemyslaw Roguski |
| 6 | + blog_tags: |
| 7 | + - patterns |
| 8 | + - zero-trust |
| 9 | + - security |
| 10 | + - acs |
| 11 | + - runtime-security |
| 12 | + - openshift |
| 13 | +--- |
| 14 | +:toc: |
| 15 | +:imagesdir: /images |
| 16 | + |
| 17 | +== From gates to guards |
| 18 | + |
| 19 | +In the https://validatedpatterns.io/blog/2026-06-29-zero-trust-network-policies/[first article of this series], we locked every door: default-deny network policies block lateral movement and data exfiltration even when a vulnerability is exploited faster than you can patch. |
| 20 | + |
| 21 | +But locking doors only works if someone is watching what happens inside the room. A true zero trust architecture — as defined by https://csrc.nist.gov/pubs/sp/800/207/final[NIST SP 800-207] — demands continuous runtime verification, not just static access controls. |
| 22 | + |
| 23 | +== ACS as the zero trust brain |
| 24 | + |
| 25 | +The https://validatedpatterns.io/patterns/layered-zero-trust/[Layered Zero Trust Validated Pattern] deploys Red Hat Advanced Cluster Security with four custom security policies that go far beyond the default configuration. These policies are split into two operational categories: |
| 26 | + |
| 27 | +*Deploy-time alerting* — catches missing network boundaries before they reach production: |
| 28 | + |
| 29 | +* Alerts when a deployment lacks an *ingress* NetworkPolicy |
| 30 | +* Alerts when a deployment lacks an *egress* NetworkPolicy |
| 31 | + |
| 32 | +*Runtime termination* — neutralizes active threats in real time: |
| 33 | + |
| 34 | +* *Privilege escalation prevention* — instantly kills any pod that attempts `sudo`, `su`, `pkexec`, `nsenter`, or `unshare` |
| 35 | +* *Suspicious exec termination* — immediately terminates pods running reconnaissance tools like `nmap`, `nc`, or `ncat` |
| 36 | + |
| 37 | +The result: network policies block the attacker's escape routes, and ACS eliminates the threat entirely — even if a configuration was missed. |
| 38 | + |
| 39 | +== See it in action |
| 40 | + |
| 41 | +The article includes a video demonstration of the "assume a breach" scenario. An attacker who has gained code execution inside a pod attempts to run reconnaissance commands. Within seconds, ACS detects the anomalous behavior and terminates the pod — no human intervention required. |
| 42 | + |
| 43 | +== Read the full article |
| 44 | + |
| 45 | +For the complete deep dive into how ZTVP implements the NIST 800-207 control loop with ACS as the policy decision and enforcement engine, read the full article on the Red Hat blog: |
| 46 | + |
| 47 | +**https://www.redhat.com/en/blog/lights-real-time-threat-response-red-hat-advanced-cluster-security[Lights On! Real-Time Threat Response with Red Hat Advanced Cluster Security]** |
| 48 | + |
| 49 | +== Get started |
| 50 | + |
| 51 | +The Layered Zero Trust Validated Pattern is open source: |
| 52 | + |
| 53 | +* https://validatedpatterns.io/patterns/layered-zero-trust/[Pattern documentation] |
| 54 | +* https://github.com/validatedpatterns/layered-zero-trust[Source repository] |
| 55 | + |
0 commit comments