VM Workload and Kubernetes Cluster Security
Focus
Focus
Prisma AIRS

VM Workload and Kubernetes Cluster Security

Table of Contents

VM Workload and Kubernetes Cluster Security

Prisma AIRS AI Runtime Firewall post-deployment configurations in Strata Cloud Manager and cloud to protect VM workloads and Kubernetes clusters.
Where Can I Use This?What Do I Need?
  • Secure VMs and Kubernetes
This section covers the configurations you need to secure your VM workloads/vNets and Kubernetes clusters, and route traffic after you apply the Prisma AIRS AI Runtime Firewall deployment Terraform template in your cloud environment.
In this section you will:
  • Configure the following in Strata Cloud Manager:
    • Interfaces
    • Zones
    • NAT Policy
    • Routers
    • Security Policies
  • Secure VM workloads only for public clouds
  • Secure Kubernetes clusters in private and public clouds
  • Install a Kubernetes application with Helm
  • (Optional) Configure labels in your cloud environment for manual deployments.
    The Prisma AIRS AI Runtime Firewall deployment Terraform you generate from Strata Cloud Manager, automatically adds the required labels to organize your Prisma AIRS AI Runtime Firewall. For manual deployments, ensure you have the following labels (key-value pairs) in your Terraform template.
    • Add the following labels (key-value pairs) under Tags in the Terraform template file under your downloaded path `<azure|aws-deployment-terraform-path>/architecture/security_project/terraform.tfvars`. The value of these keys must be unique.
    • For GCP: `paloaltonetworks_com-trust` and `paloaltonetworks_com-occupied`.
    • For Azure and AWS: `paloaltonetworks.com-trust` and `paloaltonetworks.com-occupied`.
    • Ensure the network interface name in the security_project Terraform is suffixed by `-trust-vpc`.
Prisma AIRS AI Runtime Firewall is only supported for public clusters on GCP, Azure, and AWS cloud platforms and a few private clouds such as OpenShift, ESXi, and KVM.
Before proceeding, complete the following steps:
  • Complete the deployment steps in AI Runtime Firewall, VM-Series, and CNGFW Deployment in Public Clouds for your cloud to save and download the Terraform template.
  • Unzip and navigate to the `<unzipped-folder>` that has the following
    structure:
    |____architecture |____LICENSE |____README.md |____security_project |____application_project |____helm |____modules
  • (Optional) Enable SSL/TLS decryption on Prisma AIRS AI Runtime Firewall to decrypt traffic between AI applications and AI models:
    The decryption helps you to detect and enforce AI security protection.
    These steps involve creating a decryption policy and exporting the Root CA from Strata Cloud Manager.
    • Select ConfigurationNGFW and Prisma AccessSecurity ServicesDecryption.
    • Add a new decryption policy rule, or modify an existing one.
    • Configure the source and destination zones.
    • Under "Action and Advanced Inspection", set the action to decrypt.
    • Select the decryption type to SSL Forward Proxy.
    • Select a Decryption Profile to perform additional checks on traffic that matches the policy rule.
    • Select ConfigurationNGFW and Prisma AccessObjectsCertificate Management.
    • Select Root CA and click Export Certificate.
    • Push the changes to the Prisma AIRS AI Runtime Firewall and wait for the push to complete.