VM Workload and Kubernetes Cluster Security
Prisma AIRS AI Runtime Firewall post-deployment configurations
in Strata Cloud Manager and cloud to protect VM workloads and Kubernetes
clusters.
| Where Can I Use This? | What Do I Need? |
- Secure VMs and Kubernetes
|
|
This section covers the configurations you need to secure your VM workloads/vNets and
Kubernetes clusters, and route traffic after you apply the Prisma AIRS AI Runtime Firewall deployment Terraform template in
your cloud environment.
In this section you will:
- Configure the following in Strata Cloud Manager:
- Interfaces
- Zones
- NAT Policy
- Routers
- Security Policies
- Secure VM workloads only for public clouds
- Secure Kubernetes clusters in private and public clouds
- Install a Kubernetes application with Helm
(Optional) Configure labels in your cloud environment for
manual deployments.
The Prisma AIRS AI Runtime Firewall deployment
Terraform you generate from Strata Cloud Manager, automatically
adds the required labels to organize your Prisma AIRS AI Runtime Firewall. For manual
deployments, ensure you have the following labels (key-value pairs)
in your Terraform template.
Add the following labels (key-value pairs) under Tags in
the Terraform template file under your downloaded path
`<azure|aws-deployment-terraform-path>/architecture/security_project/terraform.tfvars`.
The value of these keys must be unique.
For GCP: `paloaltonetworks_com-trust` and
`paloaltonetworks_com-occupied`.
For Azure and AWS:
`paloaltonetworks.com-trust` and
`paloaltonetworks.com-occupied`.
Ensure the network interface name in the security_project
Terraform is suffixed by `-trust-vpc`.
Prisma AIRS AI Runtime
Firewall is only supported for public clusters on GCP, Azure, and AWS cloud
platforms and a few private clouds such as OpenShift, ESXi, and KVM.
Before proceeding, complete the following steps:
- Unzip and navigate to the `<unzipped-folder>` that has the following
structure:
|____architecture
|____LICENSE
|____README.md
|____security_project
|____application_project
|____helm
|____modules
(Optional) Enable SSL/TLS decryption on Prisma AIRS AI Runtime Firewall to decrypt traffic
between AI applications and AI models:
The decryption helps you to detect and enforce AI security protection.
These steps involve creating a decryption policy and exporting the
Root CA from Strata Cloud Manager.
Select .
Configure the source and destination zones.
Under "Action and Advanced Inspection", set the action to
decrypt.
Select the decryption type to SSL Forward
Proxy.
Select a
Decryption
Profile to perform additional checks on traffic
that matches the policy rule.
Select .
Select Root CA and click Export
Certificate.
Push the changes to the Prisma AIRS AI
Runtime Firewall and wait for the push to complete.