Meet Clair, open source vulnerability analysis on containers

DockerCon Barcelona has lots of buzz coming out of it and we will be covering all of the action here this week.  We wanted to lead off with a story that was actually broke this past Friday from the CoreOS team. They have released a new open source tool called Clair. Clair performs vulnerability analysis on containers. As part of CoreOS’s Quay your container infrastructure can be automatically scanned for vulnerabilities.

I had a chance to speak with Joey Schorr from CoreOs one of the engineers behind Clair. Calling it vulnerability analysis rather scanning per se is actually much more accurate. Unlike vulnerability scanning in traditional servers and infrastructure, Clair is looking at manifests and other registry like indexes and seeing what packages or components are out of date. If out of date packages or components are found, Clair and Quay can notify you.

Schorr told me they purposefully did not build in patching or other remediation beyond notification. This seems something that a 3rd party may want build using APIs built in Claire.

Below is a slide show showing more about Clair and Quay’s new service:

[embeddoc url=”https://cloudnativenow.com/wp-content/uploads/2015/11/Identifying-Common-Vulnerabilities-and-Exposures-in-Containers-Final.pptx” viewer=”microsoft”]

It is good to see CoreOS and other container vendors hitting the container security question head on. This reminds me of the early years of the VMware era where many were questioning the security of hypervisors and the result was an explosion of hypervisor/VM security tools. Some of these were acquired by VMware directly others formed a vibrant ecosystem. I suspect a similar path will be forged here.

Stay tuned for more DockerCon 15 news this week.

Alan Shimel

Alan Shimel is founder, CEO and editor-in-chief of Techstrong Group, a Futurum company, and a member of Futurum's executive leadership team. A technology entrepreneur, media executive and industry commentator, Shimel has spent more than three decades building businesses, communities and media platforms serving enterprise technology professionals, including co-founding StillSecure, a network security company, and the DevOps Institute, a DevOps certification and training body. At Techstrong, he leads a portfolio of media brands including DevOps.com, Security Boulevard, Cloud Native Now, Techstrong AI, Techstrong IT, Digital CxO, Platform Engineering, Techstrong Semi and Techstrong TV, along with a growing portfolio of events, educational programs and digital communities. With more than 25 years of experience in cybersecurity, Shimel is a familiar voice in the space and was an early advocate of the DevOps movement, helping bring DevOps practices into mainstream enterprise technology. His work today spans cybersecurity, DevOps, cloud-native technologies, artificial intelligence, semiconductors and digital transformation, and he hosts popular programs including Techstrong Gang, Shimmy Says and Still Cyber, After All These Years. He holds a Bachelor of Arts in Government and Politics from St. John's University and a Juris Doctor from New York Law School.

Alan Shimel has 116 posts and counting. See all posts by Alan Shimel