If you are using Google Cloud Security Command Center (Cloud SCC), you can forward alerts from Red Hat Advanced Cluster Security for Kubernetes to Cloud SCC. This guide explains how to integrate Red Hat Advanced Cluster Security for Kubernetes with Cloud SCC.
The following steps represent a high-level workflow for integrating Red Hat Advanced Cluster Security for Kubernetes with Cloud SCC.
Register a new security source with Google Cloud.
Provide the source ID and service account key to Red Hat Advanced Cluster Security for Kubernetes.
Identify the policies you want to send notifications for, and update the notification settings for those policies.
Start by adding Red Hat Advanced Cluster Security for Kubernetes as a trusted Cloud SCC source.
Follow the Adding vulnerability and threat sources to Cloud Security Command Center guide and add Red Hat Advanced Cluster Security for Kubernetes as a trusted Cloud SCC source. Make a note of the Source ID that Google Cloud creates for your Red Hat Advanced Cluster Security for Kubernetes integration. If you do not see a source ID after registering, you can find it on the Cloud SCC Security Sources page.
Create a key for the service account you created, or the existing account you used, in the previous step. See Google Cloud’s guide to creating and managing service account keys for details.
Create a new Google Cloud SCC integration in Red Hat Advanced Cluster Security for Kubernetes by using the Source ID and service account key.
On the RHACS portal, navigate to Platform Configuration → Integrations.
Scroll down to the Notifier Integrations section and select Google Cloud SCC.
Click New Integration (add
icon).
Enter a name for Integration Name.
Enter the Cloud SCC Source ID and Service Account Key (JSON).
Select Create (save
icon) to create the configuration.
Enable alert notifications for system policies.
On the RHACS portal, navigate to Platform Configuration → System policies.
Select the check boxes for one or more policies that you want to send alerts for.
Select Actions → Enable Notification.
In the Enable Notifications dialog box, select the check box for the Google Cloud SCC notifier.
If you have not configured any other integrations, you will see No notifiers configured!. |
Click Enable.
|