This is unreleased documentation for Runtime Enforcer 0.11-dev.

Who is this project for? The personas.

This page lists the people who use Kubewarden Runtime Enforcer, and what each of them does with it. The use cases refer to these personas.

Kubewarden Runtime Enforcer personas

Persona Description

Operator

Installs Runtime Enforcer in a cluster and keeps it running. Makes sure that the nodes meet the kernel and container runtime requirements. Configures the telemetry collector.

Platform engineer

Owns the runtime security posture of the cluster. Selects the namespaces where learning runs. Sees which workloads have a policy, in which mode, and which policies are noisy. Decides when teams move to protect mode.

Application team

Owns one or more workloads. Reviews the proposal for a workload and promotes it. Adds expected executables to the allow-list and acknowledges the violations that it accepts. Does these tasks with labels and annotations on the custom resources, or with the kubectl plugin.

Security engineer

Reads the violations and the exported events. Decides when a blocked or reported executable is a risk. Sets alerts on the violation metrics.

Integrator

Builds tools on top of Runtime Enforcer. Reads the custom resources and the OpenTelemetry events. Examples are a dashboard, a SIEM, or a GitOps pipeline that applies the same policy to many clusters.

Developer

Works on Runtime Enforcer itself.