Panorama Post-Deployment Configuration for VM Workloads and Kubernetes Clusters
Panorama configurations to secure your VM workloads/vNets and Kubernetes clusters
after you deploy Panorama managed Prisma AIRS AI Runtime
Firewall.
| Where Can I Use This? | What Do I Need? |
- Secure VMs and Kubernetes Clusters
|
|
This page covers the configurations you need to secure your VM workloads/vNets
and Kubernetes clusters, and route traffic after you apply the Panorama-managed
deployment Terraform template in your cloud environment.
On this page, you will:
Configure the following in Panorama:
- Interfaces
- Zones
- NAT Policy
- Routers
- Security Policies
- Secure VM workloads only for public clouds
- Secure Kubernetes clusters in public and private clouds
- Install a Kubernetes application with Helm
(Optional) Configure labels in your cloud environment
for manual deployments.
The deployment Terraform you generate from Strata Cloud Manager,
automatically adds the required labels to organize your Prisma AIRS AI Runtime Firewall. For
manual deployments, ensure you have the following labels
(key-value pairs) in your Terraform template.
Add the following labels (key-value pairs) under Tags
in the Terraform template file under your downloaded
path
`<azure|aws-deployment-terraform-path>/architecture/security_project/terraform.tfvars`.
The value of these keys must be unique.
For GCP: `paloaltonetworks_com-trust` and
`paloaltonetworks_com-occupied`.
For Azure and AWS:
`paloaltonetworks.com-trust` and
`paloaltonetworks.com-occupied`.
Ensure the network interface name in the
security_project Terraform is suffixed by
`-trust-vpc`.
Prisma AIRS AI Runtime Firewall
is only supported for public clusters on GCP, Azure, and AWS cloud platforms and a
few private clouds such as OpenShift, ESXi, and KVM.
Before proceeding, complete the following steps:
- Unzip and navigate to the `<unzipped-folder>` that has the following
structure: