🛡️ SECURITY & IDENTITY
دفاع بالعمق
Zero-trust security: SSO, secrets management, policy enforcement, runtime detection, and certificate automation.
طبقات أمان انعدام الثقة
الهوية
Keycloak
SSO OIDC عبر جميع الخدمات
الأسرار
Vault + ESO
مشفرة في حالة السكون، مزامنة إلى الحاويات
السياسة
Kyverno
التحكم في القبول والتحويل والتحقق
وقت التشغيل
Falco
كشف الشذوذ المبني على eBPF
الفحص
Kubescape
امتثال CIS وNSA وMITRE
تسجيل دخول موحد في كل مكان
تسجيل دخول Keycloak واحد يمنح الوصول إلى كل خدمة في المنصة. لا بيانات اعتماد منفصلة.
إدارة الأسرار
صفر أسرار في Git. صفر أسرار في etcd. كل شيء يمر عبر Vault.
graph TD TF["Terraform"]:::terraform VAULT["Vault HA / 3 Raft replicas Encrypted at rest"]:::vault CSS["ClusterSecretStore vault-backend"]:::store ES["ExternalSecret Per-app, per-namespace"]:::external KS["Kubernetes Secret Mounted as env or volume"]:::k8s POD["Pod Consumes secret transparently"]:::pod TF -->|"Provision secrets"| VAULT VAULT --> CSS CSS --> ES ES --> KS KS --> POD classDef terraform fill:#0e3a3a,stroke:#06b6d4,color:#67e8f9,stroke-width:2px classDef vault fill:#2e2a0e,stroke:#facc15,color:#fde68a,stroke-width:2px classDef store fill:#14332a,stroke:#4ade80,color:#86efac,stroke-width:2px classDef external fill:#2e1a47,stroke:#a78bfa,color:#c4b5fd,stroke-width:2px classDef k8s fill:#1e3a5f,stroke:#60a5fa,color:#93c5fd,stroke-width:2px classDef pod fill:#2e1a0e,stroke:#f97316,color:#fdba74,stroke-width:2px
security.imageProxyTitle
security.imageProxyDesc
🔒
security.imageProxy1Title
security.imageProxy1Desc
🔄
security.imageProxy2Title
security.imageProxy2Desc
🚫
security.imageProxy3Title
security.imageProxy3Desc
جميع المكونات
Keycloak
productionEnterprise identity and access management with OIDC, SAML, social login, and LDAP integration.
الدور: Centralized SSO for all platform services — Vault, Harbor, Grafana, ArgoCD, OneDev, Devtron
HashiCorp Vault
productionSecrets management, encryption as a service, and privileged access management.
الدور: HA deployment (3-replica Raft cluster) storing all platform secrets, DNS credentials, TLS certificates
External Secrets Operator
productionKubernetes operator that synchronizes secrets from external stores into Kubernetes secrets.
الدور: Bridges Vault ↔ Kubernetes: syncs secrets to pods, pushes certificates back to Vault
cert-manager
productionAutomatic TLS certificate management with Let's Encrypt ACME protocol support.
الدور: Automated certificate issuance via DNS-01 challenges with Cloudflare
Kyverno
productionKubernetes-native policy engine for validation, mutation, and generation of resources.
الدور: Enforces security policies, injects PriorityClasses via mutation for charts that don't propagate values, image proxy rewriting to Harbor
Kubescape
deployedKubernetes security platform for continuous scanning against NSA, MITRE, and CIS benchmarks.
الدور: Compliance scanning and hardening recommendations
Open AppSec
deployedML-based web application firewall and API security.
الدور: WAF protection for exposed services