|
This is unreleased documentation for Runtime Enforcer 0.11-dev. |
Who is this project for? The personas.
This page lists the people who use Kubewarden Runtime Enforcer, and what each of them does with it. The use cases refer to these personas.
Kubewarden Runtime Enforcer personas
| Persona | Description |
|---|---|
Operator |
Installs Runtime Enforcer in a cluster and keeps it running. Makes sure that the nodes meet the kernel and container runtime requirements. Configures the telemetry collector. |
Platform engineer |
Owns the runtime security posture of the cluster. Selects the namespaces where learning runs. Sees which workloads have a policy, in which mode, and which policies are noisy. Decides when teams move to protect mode. |
Application team |
Owns one or more workloads. Reviews the proposal for a workload and promotes
it. Adds expected executables to the allow-list and acknowledges the
violations that it accepts. Does these tasks with labels and annotations on
the custom resources, or with the |
Security engineer |
Reads the violations and the exported events. Decides when a blocked or reported executable is a risk. Sets alerts on the violation metrics. |
Integrator |
Builds tools on top of Runtime Enforcer. Reads the custom resources and the OpenTelemetry events. Examples are a dashboard, a SIEM, or a GitOps pipeline that applies the same policy to many clusters. |
Developer |
Works on Runtime Enforcer itself. |