Overview
The On-Prem AI Infrastructure Platform secures containerized AI workloads at two layers. StackRox provides runtime vulnerability scanning and threat detection across every Kubernetes cluster, and the Harbor registry with built-in Trivy scans every container image before it is deployed.StackRox protection is deployed automatically. Every new cluster created through
Polystack K8SaaS is enrolled with no manual onboarding.
Architecture
Components
- Runtime Security
- Image and Registry Scanning
Sensor and Collector are deployed to each cluster automatically, so every cluster is
covered from creation.
Coverage
Before deployment
Before deployment
Harbor with Trivy scans images in the registry, so vulnerable images are identified
before they are deployed.
At runtime
At runtime
StackRox continuously scans running workloads and monitors process and network activity
on every node through the Collector.
Across the fleet
Across the fleet
StackRox Central gives security teams one view of vulnerabilities and policy violations
across all Kubernetes clusters on the platform.
Next Steps
Operator Framework
The other platform add-on deployed to every cluster.
MLOps Platform
The AI cluster template, which includes the Harbor registry.
Kubernetes Security
Security configuration for Polystack K8SaaS clusters.
Unified Console
One portal and single sign-on across the platform.
