Skip to content
This repository has been archived by the owner on Jun 10, 2024. It is now read-only.

Security: CY22 Q3 Q4, CY23 Roadmap

Sumit Jaiswal edited this page Oct 17, 2022 · 2 revisions

Status: PLANNED

This is an uncommitted roadmap for CY22 Q3 & Q4, CY23 (some things might get dropped or added over the period).

Feedback is welcome in #security-automation on IRC Libera.chat.

Ansible Security Working Group:

Security Automation Group.

Ansible supported Security Platform Collections:

Cisco ASA, IBM Qradar, Splunk ES, Trendmicro Deepsecurity,

Follow our progress:

1. Develop roles to:

  • Install distributed security platform e.g IDS/IPS agent.
  • Link IDS logs to security operations tools e.g. SIEM/SOAR
  • IDS alerts to SIEM. SIEM uses EDA to run controller job to fix, which needs to run close to edge devices i.e. mesh exec node

2. Kubernetes and Container security

We've begun collaborating with Kubernetes and Container security platforms and vendors to provide an Ansible integration solution for automating Kubernetes and Container security use cases. Vendors planned:

  • RedHat StackRox
  • Palo Alto Networks Prisma Cloud Compute Edition
  • Aqua Container Security
  • Anchore

3. PKI / Certificate handling for EDGE

a. Identify key PKI platforms to integrate through modules eventually promoted into Certified content collections Candidates:

  • Entrust
  • Digicert
  • Thales
  • Utimaco
  • Amazon Web Services (AWS)
  • Azure and Google Cloud Platform (GCP)

b. Identify key use cases to integrate through roles eventually promoted into Validated content collections Potential examples:

  • Workload Identities management
  • Life cycle of certificates across the organization
  • SSH Key Management
  • IaaS Provider Secret
  • Key and Certificate Management

ansible.security meta collection:

Security.

(ARchived) Working groups

Working groups are now in the Ansible forum

Ansible project:
Community, Contributor Experience, Docs, News, Outreach, RelEng, Testing

Cloud:
AWS, Azure, CloudStack, Container, DigitalOcean, Docker, hcloud, Kubernetes, Linode, OpenStack, oVirt, Virt, VMware

Networking:
ACI, AVI, F5, Meraki, Network, NXOS

Ansible Developer Tools:
Ansible-developer-tools

Software:
Crypto, Foreman, GDrive, GitLab, Grafana, IPA, JBoss, MongoDB, MySQL, PostgreSQL, RabbitMQ, Zabbix

System:
AIX, BSD, HP-UX, macOS, Remote Management, Solaris, Windows

Security:
Security-Automation, Lockdown

Tooling:
AWX, Galaxy, Molecule

Communities

Modules:
unarchive, xml

Plugins:
httpapi

Wiki

Roles, Communication, Reviewing, Checklist, TODO

Clone this wiki locally