Skip to main content

NeuVector

NeuVector delivers Full Lifecycle Container Security with the only cloud-native, Kubernetes security platform providing end-to-end vulnerability management, automated CI/CD pipeline security, and complete run-time security including the industry’s only container firewall to protect your infrastructure from zero days and insider threats.

neuvector.com, docs, code

Content​

Features​

Trainings​

Versions​

v5.3.0​

v5​

  • New scanning targets
  • Zero-drift process and file protection
  • Split policy mode
  • Web app firewall rule detection
  • CRD updates
  • Enhanced Rancher Integration
  • Automated promotion of group nodes

Installation​

Rancher App​

  • In Rancher, from your cluster, go to Apps > Charts and look for NeuVector and click on Install

  • In Step 2 > Edit Options

    • In Container Runtime, make sure you select the right runtime (containerd for instance with AKS)
    • In Ingress Configuration, check the Manager Ingress Status box, fill Manager Ingress Host (neuvector.demo for example)
  • In Step 2 > Edit YAML, edit the content to add ingressClassName

    manager:
    ingress:
    annotations:
    nginx.ingress.kubernetes.io/backend-protocol: HTTPS
    enabled: true
    host: neuvector.demo
    ingressClassName: nginx
    path: /
    secretName: null
    tls: false
  • Click on Install and review the overall installation process

  • Once installed correctly (all pods running fine), go to Service Discovery > Ingresses

    • In cattle-neuvector-system namespace, click on the target link
    • Log in with admin/admin and update immediatly the password

Q&A​

Q: It is possible to export reports and scans in pdf and automate the creation sending them via email for example?

A: Yes, this could be done by leveraging the API

Q: Is it possible to customize login UI?

A: The name can be changed but no other customization for the moment (a feature request has been created to cover this part)

Q: Must NeuVector be installed into each working cluster or is it possible to have one central NeuVector cluster and route to it from each downstream cluster?

A: The components such as the scanner, enforcer, etc. must be installed in each cluster but you can federate clusters together so there's a single UI to manage multiple clusters

Q: Can we "ignore/silence" a vulnerability so it doesn't show in the reporting?

A: You can "accept" vulnerabilities that negate them coming up in reports/alerts, reports can also filter out vulnerabilities with (for example) a low CVE score, No fix, etc. So you could generate a list of all known CVE's in your environment, filter by no fix and then bulk accept those

Q: How much of a performance overhead is the enforcer?

A: This is documented in the FAQ at point 2

Known issues​

  • Timeout while on the web interface
    • Refresh the page and authenticate again

Articles​

Alternatives​

Recipes​

How to scan control plane nodes​

By default, only worker nodes are scanned. You can change this by adapting the tolerations of the enforcer when installing NeuVector. The default can be seen in values.yaml (enforcer / tolerations). Depending on the Kubernetes distribution, the taints may be different on non-worker nodes.

To tolerate all possible taints, a config would be:

enforcer:
tolerations:
- operator: "Exists"

Integrations​

Harbor​

Scanning​

GitLab​

Scan for Vulnerabilities during Gitlab Build Pipeline

Updates from plugin (MR are not looked at...):

  • Scan a private registry
# GitLab Project > Settings > CI/CD > Variables > CONTAINER_REGISTRY_USER & IMAGE_REGISTRY_PASSWORD

include:
- remote: 'https://gitlab.com/neuvector/gitlab-plugin/-/raw/master/scan.yml'

stages:
- scan

neuvector_scan:
stage: scan
variables:
image_registry_url: "https://registry-1.docker.io"
image_registry_user: $CONTAINER_REGISTRY_USER
image_registry_password: $IMAGE_REGISTRY_PASSWORD
image_repo: "library/alpine"
image_tag: "3.6"
nv_registry_user: $CONTAINER_REGISTRY_USER
nv_registry_password: $IMAGE_REGISTRY_PASSWORD
scan_layers: "false"
high_vul_to_fail: 5
medium_vul_to_fail: 9
vul_names_to_fail: "CVE-2020-1971, CVE-2020-1972"