You've Been Running a Kubernetes Security Model in NSX and Didn't Even Know It
One of the blockers to moving VMs off vSphere and onto Kubernetes is losing NSX and the protection it provides. Security teams that have spent years building out distributed firewall policy look at Kubernetes and are, quite understandably, alarmed by the flat network and the fact that any workload can reach any other by default. How will they enforce east-west traffic controls? Will they be able to replicate NSX distributed firewall rules with the same granularity?