Note: This article is translated from NeuVector Workflow .
NeuVector supports the complete CI/CD process and can be easily integrated into workflows to provide security protection throughout the entire development and deployment process.
Dev and CI
NeuVector can be integrated into Dev (development) and CI (continuous integration) processes for automatic vulnerability scanning. Using NeuVector Jenkins plugins and image repository scanning, image scanning can be performed during the Dev and CI stages.
NeuVector ensures Dev and CI security in the following ways:
-
Dev security:
-
Integration with Jenkins plugins.
-
Verification of builds during development.
-
Build failure if security issues are not passed.
-
-
Security checks during testing:
-
Runtime behavior assessment.
-
Vulnerability scanning.
-
-
Image repository security: Image/image repository scanning.
In addition, NeuVector can be used to analyze network connections and container behavior during automated application testing to predict any issues in staging or production.
CD and Production
NeuVector can be deployed for compliance testing and security auditing before and during production.
NeuVector ensures CD (continuous deployment) and production security through the following methods:
-
Pre-production/staging
-
CIS benchmark testing:
-
Environment auditing and reporting.
-
Role-based access control.
-
-
Security auditing:
-
Learning, creating, and testing security policies.
-
Vulnerability scanning.
-
-
Connection debugging.
-
-
Production container security:
-
Automatic policy generation or import.
-
Monitoring and protecting containers from threats and violations.
-
Automatic isolation and response rules for alerts.
-
Integration with SIEM for reporting and logging.
-
A multi-faceted security platform can combine network security, container inspection, and host security to protect containers at runtime.