Securing containerized workloads deployed in cloud-native environments requires
applying granular security policies, but traditional controls often lack the
necessary context of who is accessing which application. This visibility gap makes
it difficult for security teams to enforce fine-grained access, often resulting in
overly permissive rules that unnecessarily expand the attack surface. CN-Series
firewalls now provide qualification and official support for User-ID™ in Kubernetes
as CNF mode. This integration allows your security team to transition security
enforcement from relying solely on network topology to leveraging precise user
identity information. When you implement User-ID™ with CN-Series, you gain improved
visibility into application usage, enabling you to apply security policy controls
based on the specific user accessing the service. This capability is specifically
designed for CN-Series deployments operating within the cloud-native Kubernetes
platform. By binding user context to traffic, you ensure security incidents logged,
reported, and analyzed provide a complete picture rooted in user actions,
transforming the way you approach forensics. You reduce the attack surface
significantly by enforcing need-based user access and ensure that security policies
are consistently applied across your distributed microservices. For more
information, see
User-ID.