The Container Asset Overview feature provides security visualization and network topology for your container assets, including clusters, containers, images, and applications. This feature helps you monitor the security status of your container assets and understand the network connections between them. This topic describes how to view your container asset overview.
Scenarios
Compliance with classified protection requirements
The network topology of cloud assets helps you meet the classified protection compliance requirements.
Visualization
Provides visualization of ports exposed to the Internet, and security management capabilities from dimensions such as clusters, containers, images, and applications.
Prerequisites
The servers where the target clusters are deployed are bound to the Ultimate edition.
Subscription: When you Purchase Security Center or upgrade the edition, set Edition to Ultimate.
Pay-as-you-go: When you Purchase Security Center, set Host and Container Security to Yes, and then complete the Ultimate edition authorization for the servers where the target clusters are deployed. For more information, see Configure protection editions or levels (pay-as-you-go).
The image vulnerability data displayed on the Container Asset Overview page is obtained from the Container Image Scan feature. If you need to view image security risks, you must first enable the Container Image Scan feature and run image security scans. For more information, see Enable container image scan and Run image security scans.
If you have not enabled the Container Image Scan feature, you can only view the vulnerability risks on the servers where the current cluster is deployed and the cluster network topology on the Container Asset Overview page. You cannot view the container vulnerability risks in the cluster. To improve the security of your container runtime environment, we recommend that you enable the Container Image Scan feature.
Background information
Security Center automatically refreshes the container network topology and cluster security risk information on the Container Asset Overview page every minute to ensure that you can view the latest network topology and security risk information.
Procedure
Log on to Security Center console.
In the left-side navigation pane, choose
On the Overview page, click the Container Asset Overview tab.
On the Container Asset Overview tab, view the container asset overview of your assets.
The Container Asset Overview tab consists of the following seven areas. You can click the links below to view the data and supported operations for each area:
Description
View the security score of your assets
The security score calculated by Security Center based on the overall security status of your assets. A higher score indicates fewer security risks. For more information about the security score, see Security score.
Click Handle Now to expand the Security Score Details panel, where you can handle security risks in your assets.
View the number of clusters and the number of assets at risk
Black numbers indicate the total number of clusters. Red numbers indicate the number of assets at risk.
Click the Cluster area to go to the Cluster tab of the page to view cluster details. For more information, see View cluster information.
Switch the display perspective of the cluster network topology
Click Internet Perspective or Cluster Perspective above the cluster topology to switch the display perspective.
View the basic information and security status of a cluster
In the cluster topology, click the cluster icon to view the Cluster information, Cluster risk, Image Information, and Protection Policy tabs in the right-side panel.
Cluster information tab
View the basic information of the cluster, including the cluster Name, Cluster Type, Region, and Cluster Status. You can also view the counts of Namespace, Pods, Nodes, Applications, and Images in the cluster.
Cluster risk tab
View the security risks of the cluster, including Alert, Baseline Risk, and Image Vul(s). Click Details next to a security risk to go to the asset details page or the Container Image Scan vulnerability list, where you can view and handle the detected security risks. For more information about handling security risks, see View and handle alert events, Vulnerability fix overview, and View image security scan results.
Image Information tab
View the image list of the cluster. For image repositories not added to Security Center, click Add Now on the right side to go to the Container Image Scan page, where you can add the image repository to Security Center. For more information, see Add image repositories to Security Center.
Full Protection for Hosts and Containers tab
View the Defense Details of the cluster, including Blocked Alerts in the Last 7 Days, Rules, and Defense Status. Click Create Rule to expand the Create Rule panel, where you can add protection policies for the cluster.
Set the time range for the cluster network topology
On the Container Asset Overview tab, the container asset overview data for the last 7 days is displayed by default. You can filter the time range as needed. The available time range is the last 1 to 7 days.
Enable or disable Container Network Topology for a cluster
The Container Network Topology feature is disabled for all clusters by default.
ImportantEnabling the Container Network Topology feature consumes a small amount of CPU resources. The container visualization capability also requires real-time traffic data collection, which increases log volume. Even if Global Log Filtering is enabled, traffic deduplication filtering does not apply to the container visualization feature. Therefore, after enabling Container Network Topology, more log storage space is consumed. We recommend that you enable the Container Network Topology feature only for clusters whose risk status you need to monitor.
You can perform the following operations to enable or disable the Container Network Topology feature. After enabling or disabling this feature for all clusters, you can also enable or disable it for individual clusters.
Click the
or
icon on the right side of Cluster Overview to enable or disable the Container Network Topology feature for all clusters.In the cluster topology, click the target cluster icon. In the right-side panel, on the Cluster information tab, click the
or
icon next to Container Network Topology to enable or disable the Container Network Topology feature for a single cluster.
After enabling the Container Network Topology feature for a cluster, you can follow Step 5 below to view the container network topology of the target cluster and obtain the risk status of each node in the topology.
Export the container asset overview
Click the download
icon to export the container asset overview as a PNG file.If the Container Network Topology feature is enabled for a cluster (for more information, see the "Enable or disable Container Network Topology for a cluster" section in the previous step), the container network topology displays the communication links between all containers in the cluster, with applications as nodes. In the cluster topology, click the
icon below the target cluster icon to view the container network topology of the target cluster.You can also click the target cluster icon. In the right-side panel, on the Cluster Information tab, click View next to Container Network Topology.
NoteFor very large clusters, the container asset overview is collapsed by default.
The left side of the page provides the Show only connected applications, Display port information, and Hide lines features. You can enable or disable these features based on your display requirements.
The left side of the page also lists all namespaces in the cluster. You can click the
or
icon next to a namespace to hide or show the namespace. You can also click the
or
icon to expand or collapse the applications under the namespace in the container asset overview.After expanding the applications under a namespace, click an application icon in the container asset overview to view the pod information, Image Information, and Network Connection tabs.
On the pod information tab, hover the pointer over a pod name to open the pod details dialog box. Click View assets in the dialog box to go to the page, where you can view the Vulnerability and Alerts of the pod.