HN user

robertwinter

4 karma
Posts6
Comments6
View on HN

Developers and operators in today’s digital world are facing an ever-increasing set of regulatory requirements, security challenges and privacy concerns. In addition to constant attacks on IT assets there is growing legal pressure to deliver and maintain regulatory guidelines in our networked world. Requirements such as PCI-DSS, HIPAA, GDPR or SOC2 are becoming the pre-requisite of any operation in various industries.

Modern cloud native architectures and Kubernetes provide tools to address these demands, but the knowledge of these tools and methods are not widely understood. Today what is needed most is guidance on what exists and how best to use the right resources to meet the security and compliance requirements while still benefiting from the speed and agility Cloud Native environments offer.

In this video Johan Tordsson, CTO of Elastisys, provides provide a deep dive on security development tools and open source Kubernetes services available to meet these growing needs.

In a July 16, 2020 ruling dubbed “Schrems 2,” the European Court of Justice ruled that the EU-U.S. “Privacy Shield” agreement does not provide adequate protection of personally identifiable information under the General Data Protection Regulation (GDPR).

In essence, the Schrems 2 ruling means that U.S.-owned cloud providers such as Google, Amazon Web Services (AWS), and Microsoft Azure cannot be used to store data about European citizens without violating the GDPR. You know, the regulation that famously can fine violators 20 million Euros or 4% of annual revenue, whichever is larger.

Read how Kubernetes and cloud-native projects can be an enabler for cloud-agnostic GDPR compliance.

[dead] 6 years ago

Interested in how to architect your Kubernetes environments for GDPR compliance?

Check out this video and slides to also learn how cloud native technologies can be a solution for the fall of the EU-US data transfer agreement Privacy Shield.

Description

GDPR is now 2 years old and it has had a significant impact on technology companies working in Europe. On July 16, 2020 dealing with GDPR got significantly harder because the EU court of justice threw out the existing Privacy Shield agreement between the US and EU, leaving US companies facing serious challenges on how to deliver their cloud native solutions in Europe. But have no fear, there are ways to address this challenge utilizing Kubernetes. In this session Robert Winter, CEO at Elastisys provides a summary of the key elements of GDPR and recent Privacy Shield ruling and what it means. Then Cristian Klein, Elastisys Senior Cloud Architect, goes over the resources available to Kubernetes users to navigate through these tricky waters and the processes needed to meet current privacy requirements. The Kubernetes and Cloud Native ecosystem offers strong tools to address privacy and Cristian provides technical guidance in meeting the GDPR needs. Many of the same requirements discussed in this video also applies to meeting the new CCPA (California Consumer Privacy Act) and growing number of State Privacy requirements in the US. So in addition to learning how to meet EU needs this video offers valuable information on how Kubernetes and cloud native technologies will be instrumental in meeting these future needs in the US.

Agenda

Review GDPR & Privacy Shield ruling and its implications (25 min) Tools and process to address GDPR/Privacy with Kubernetes and Cloud Native tools (25 min)

This year's KubeCon + CloudNativeCon EU is a wrap! The conference was virtual but still packed with 4 days of updates, trends and use cases from all the different projects, sponsors, vendors and end users that make up the cloud native ecosystem.

Read this blog post for a summary of the main topics and trends: How the virtual event worked out The top news and the most interesting projects that are gaining traction The increased focus on CNCF end users Diversity in the open source community ClusterAPI GitOps Telco grade Kubernetes networking / edge native (K3s, Longhorn) Storage (Vitess, TiKV, Longhorn, Rook, OpenEBS, NATS) Security (Trivy, OPA, Falco, SOPS, SPIFFE, SPIRE)

We also did a video summary with more details if you like that format: https://elastisys.com/summary-kubecon-cloudnativecon-eu-the-...

If you just want to skim the slides to the video they are available here: https://elastisys.com/wp-content/uploads/2020/08/KubeCon-Clo...

As of this summer, the option to use the Privacy Shield data transfer agreement for EU citizens’ personal data transfers is gone, which more than 5000 companies have been leaning on.

Kubernetes and the cloud native software stack can help companies with a global user base by providing a cloud agnostic approach to where their applications are hosted.

In this post we argue for how companies with a global user base can skip worrying about the lack of Privacy Shield or similar future data transfer agreements by having a software infrastructure that they can use in Europe, US or in their own data centers depending the need.

What's your take, do you think multi-cloud K8s will see a rise in popularity?