Advanced network isolation
Secure connectivity
Access management
Private IP range with optional VPN connection
Feature | Shield | Security features in ESP |
|---|---|---|
Network Isolation | Provides network isolation for production and non-production servers based on EC2 instances in separate VPCs. | Provides network isolation for environments based on Kubernetes infrastructure, with isolated pods in subnet. |
VPN Support | Supports VPN connectivity with IKEv1 and IKEv2. | Maintains existing VPN connections and configurations. |
IP Allowlisting for SSH access | Is available for Shield subscribers on Cloud Platform Enterprise and has a limit of 25 IP addresses or CIDR ranges. | Preserves existing security configurations. |
Infrastructure | Is based on the traditional non-Kubernetes infrastructure. | Is based on the modern Kubernetes infrastructure. |
Performance | Supports standard performance. | Supports enhanced performance and scalability. |
Network isolation refers to a configuration where applications operate on a dedicated pool of nodes in a Kubernetes cluster. These nodes are situated in a specific set of subnets to ensure that the applications have their own isolated environment. This setup provides an additional layer of isolation beyond the standard capabilities of Kubernetes to ensure that the application does not share memory, compute, or disk resources with applications that belong to other customers.
If your application requires stringent isolation levels, this approach offers a comparable solution while preserving the inherent benefits of the Kubernetes platform.
Network isolation allows organizations to achieve a balance between enhanced security and the operational efficiency, which makes it an attractive option for businesses with high security and compliance needs.
If this content did not answer your questions, try searching or contacting our support team for further assistance.
Advanced network isolation
Secure connectivity
Access management
Private IP range with optional VPN connection
Feature | Shield | Security features in ESP |
|---|---|---|
Network Isolation | Provides network isolation for production and non-production servers based on EC2 instances in separate VPCs. | Provides network isolation for environments based on Kubernetes infrastructure, with isolated pods in subnet. |
VPN Support | Supports VPN connectivity with IKEv1 and IKEv2. | Maintains existing VPN connections and configurations. |
IP Allowlisting for SSH access | Is available for Shield subscribers on Cloud Platform Enterprise and has a limit of 25 IP addresses or CIDR ranges. | Preserves existing security configurations. |
Infrastructure | Is based on the traditional non-Kubernetes infrastructure. | Is based on the modern Kubernetes infrastructure. |
Performance | Supports standard performance. | Supports enhanced performance and scalability. |
Network isolation refers to a configuration where applications operate on a dedicated pool of nodes in a Kubernetes cluster. These nodes are situated in a specific set of subnets to ensure that the applications have their own isolated environment. This setup provides an additional layer of isolation beyond the standard capabilities of Kubernetes to ensure that the application does not share memory, compute, or disk resources with applications that belong to other customers.
If your application requires stringent isolation levels, this approach offers a comparable solution while preserving the inherent benefits of the Kubernetes platform.
Network isolation allows organizations to achieve a balance between enhanced security and the operational efficiency, which makes it an attractive option for businesses with high security and compliance needs.
If this content did not answer your questions, try searching or contacting our support team for further assistance.