You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Functionality is similar to (what I interpret as) the thoughts behind Hedgehog, 100% free OSS, focusing on existing K8s projects and on Zero-Conf|Trust|Touch XIoT management - using Git(Ops) as single source of truth of desired state.
Disclaimer: I have already suggested this in the K8s project, but it was closed and I was asked to request this feature here.
Desired state of SONiC devices are stored in Git and managed by Kcp as K3d nodes, pods and validating admission policies:
mmaymann
changed the title
K8s SONiC device management
GitOps Zero-Conf|Trust|Touch XIoT (SONiC and connected) device management
Jun 24, 2023
mmaymann
changed the title
GitOps Zero-Conf|Trust|Touch XIoT (SONiC and connected) device management
GitOps Zero-Conf|Trust|Touch XIoT (SONiC and connected device) management
Jun 24, 2023
I suggest we extend SONiC with KubernetesNative device management, to leverage the power of K8s and its ecosystem:
Backend: https://github.com/kcp-dev/kcp
SONiC: https://github.com/k3d-io/k3d
Functionality is similar to (what I interpret as) the thoughts behind Hedgehog, 100% free OSS, focusing on existing K8s projects and on Zero-Conf|Trust|Touch XIoT management - using Git(Ops) as single source of truth of desired state.
Disclaimer: I have already suggested this in the K8s project, but it was closed and I was asked to request this feature here.
Desired state of SONiC devices are stored in Git and managed by Kcp as K3d nodes, pods and validating admission policies:
-- FDO Rendezvous -> ITAM -> XIoT categorization: Unknown, XIoT1, XIoT2, ...
-- CaptivePortal -> Guest/MDM/BYOD management
-- 802.1x EAP(oL)-TLS X.509 certificate check
--- TPM_Certify_Info(2) (PCR status): Firmware vers., BootLoader, OS vers., firewall enabled, antivirus enabled, ...
--- Spire-TPM-plugin and missing Keylime functionality
--- MUD -> ITAM -> XIoT identification
--- SBOM -> ITAM -> continuous lightweight vulnerability scanning -> proactive remediation actions
-- (P)NAC/ACL: SpireServer -> SONiC NAC
-- AWS IoT Greengrass
-- Tinkerbell:
--- RackN DigitalRebar functionality
--- RedFish functionality
Monsoon opportunities after migrating SONiC to K3d:
The text was updated successfully, but these errors were encountered: