---
title: "TM1: Security Big Picture"
description: 'Security big picture for STACKIT Kubernetes: an overview of the layered security architecture across build, network, and runtime in the SKE environment.'
scfAsset:
  maintainers:
    - user: "tobias.mueller"
  managed: false
  category: "guide"
  external: false
  tags: ["Security", "SentinelOne", "wip"]
source_url: "https://framework.stackit.cloud/architecture/assetcontainer/open-contributors/tm2-security-big-picture/"
source_file: "docs/architecture/assetcontainer/open-contributors/tm2-security-big-picture.mdx"
---

<Aside type="note" title="Asset Profile">
  **Time Estimate:** 30 Minutes **Focus:** Minimum Requirements & SKE Governance
  **Learning Goals:** * Understand the Shared Responsibility Model at STACKIT. *
  Get an overview of the defense lines (Build, Network, Runtime).
</Aside>

## 1. Motivation: Why Cloud Security is Different

Unlike traditional on-premise environments ("Boundary Security"), the cloud operates on the **Shared Responsibility Model**:

- **STACKIT Responsibility:** Security **of** the Cloud (Data centers, Hardware, Host OS).
- **User Responsibility:** Security **in** the Cloud (Network config, Encryption, App Security, Data).

---

## 2. The Security Big Picture (Lines of Defense)

<Tabs>
  <TabItem label="A. Build (Shift Left)">
    **Code & Supply Chain Security** * **4-Eye-Principle:** Mandatory reviews
    for every Pull Request. * **Vulnerability Scanning:** Using **Snyk** to
    identify vulnerabilities in libraries.
  </TabItem>
  <TabItem label="B. Network">
    **ACLs & Encryption** * **SKE ACLs:** Strictly restrict access to the
    Control Plane (No `0.0.0.0/0`!). * **TLS & Ingress:** Certificate management
    via Cert-Manager for all entry points.
  </TabItem>
  <TabItem label="C. Runtime">
    **Runtime Security & Zero Trust** * **SentinelOne:** EDR protection directly
    on the Kubernetes nodes. * **'Istio' (Service Mesh):** mTLS for encrypted
    pod-to-pod communication and Zero Trust enforcement.
  </TabItem>
</Tabs>

---

## 3. Modular Pipeline Concept for Security

Security is defined as code and rolled out automatically:

<Steps>
  1. **Templates:** Integration of pre-built security modules in the CI/CD pipeline.
  2. **Secrets Manager:** Secure credential retrieval via Hashicorp Vault. 3.
  **Automated Guardrails:** Temporary opening and automatic resealing of ACLs
  during deployment.
</Steps>

---

## 4. Reference Matrix

| Layer             | Measure          | Policy / Tool            |
| :---------------- | :--------------- | :----------------------- |
| **Code**          | Snyk, Reviews    | Vulnerability Management |
| **Control Plane** | STACKIT SKE ACLs | SKE Access Control       |
| **Network**       | TLS, mTLS        | Cert-Manager / `Istio`   |
| **Workload**      | SentinelOne      | Endpoint Protection      |
