-
Notifications
You must be signed in to change notification settings - Fork 144
Security: CY22 Q3 Q4, CY23 Roadmap
Status: PLANNED
This is an uncommitted roadmap for CY22 Q3 & Q4, CY23 (some things might get dropped or added over the period).
Feedback is welcome in #security-automation
on IRC Libera.chat.
Cisco ASA, IBM Qradar, Splunk ES, Trendmicro Deepsecurity,
- Install distributed security platform e.g IDS/IPS agent.
- Link IDS logs to security operations tools e.g. SIEM/SOAR
- IDS alerts to SIEM. SIEM uses EDA to run controller job to fix, which needs to run close to edge devices i.e. mesh exec node
We've begun collaborating with Kubernetes and Container security platforms and vendors to provide an Ansible integration solution for automating Kubernetes and Container security use cases. Vendors planned:
- RedHat StackRox
- Palo Alto Networks Prisma Cloud Compute Edition
- Aqua Container Security
- Anchore
a. Identify key PKI platforms to integrate through modules eventually promoted into Certified content collections Candidates:
- Entrust
- Digicert
- Thales
- Utimaco
- Amazon Web Services (AWS)
- Azure and Google Cloud Platform (GCP)
b. Identify key use cases to integrate through roles eventually promoted into Validated content collections Potential examples:
- Workload Identities management
- Life cycle of certificates across the organization
- SSH Key Management
- IaaS Provider Secret
- Key and Certificate Management
This Wiki is used for quick notes, not for support or documentation.
Working groups are now in the Ansible forum
Ansible project:
Community,
Contributor Experience,
Docs,
News,
Outreach,
RelEng,
Testing
Cloud:
AWS,
Azure,
CloudStack,
Container,
DigitalOcean,
Docker,
hcloud,
Kubernetes,
Linode,
OpenStack,
oVirt,
Virt,
VMware
Networking:
ACI,
AVI,
F5,
Meraki,
Network,
NXOS
Ansible Developer Tools:
Ansible-developer-tools
Software:
Crypto,
Foreman,
GDrive,
GitLab,
Grafana,
IPA,
JBoss,
MongoDB,
MySQL,
PostgreSQL,
RabbitMQ,
Zabbix
System:
AIX,
BSD,
HP-UX,
macOS,
Remote Management,
Solaris,
Windows
Security:
Security-Automation,
Lockdown
Tooling:
AWX,
Galaxy,
Molecule
Plugins:
httpapi