For North America and regions outside EMEA, Red Hat Advanced Cluster Security Cloud Service for Kubernetes provides a Kubernetes-native architecture for container security, enabling DevOps and InfoSec teams to operationalize full life cycle container and Kubernetes security.
For North America and regions outside of EMEA, Red Hat® Advanced Cluster Security for Kubernetes is the pioneering Kubernetes-native security platform, equipping organizations to more securely build, deploy, and run cloud-native applications anywhere. The solution helps improve the security of the application build process, protect the application platform and configurations, and detect and respond to runtime issues.
Red Hat Advanced Cluster Security for Kubernetes lowers operational costs by reducing the learning curve for implementing Kubernetes security, provides built-in controls for enforcement to reduce operational risk, and uses a Kubernetes-native approach that supports built-in security across the entire software development life cycle, facilitating greater developer productivity.
Delivers a comprehensive view of your Kubernetes environment, including all images, pods, deployments, namespaces, and configurations.
Discovers and displays network traffic in all clusters spanning namespaces, deployments, and pods.
Vulnerability Management
Scans images for known vulnerabilities based on specific languages, packages, and image layers. Provides a dashboard highlighting the riskiest image vulnerabilities and deployments
Verifies image signatures against preconfigured keys for image attestation and integrity. Correlates vulnerabilities to running deployments, not just images Enforces policies based on vulnerability details at build time using continuous integration/continuous delivery (CI/CD) integrations.
Compliance
Assesses compliance across hundreds of controls for CIS Benchmarks, payment card industry (PCI), Health Insurance Portability and Accountability Act (HIPAA), NERC-CIP, and NIST SP 800-190 and 800-53.
Complies with key global standards: PCI DSS 4.0, SOC 2 & 3, ISO 27001:2022, ISO 27017:2015 and ISO 27018_2019.
Delivers at-a-glance dashboards of overall compliance across the controls of each standard with evidence exported to meet auditor needs.
Provides a detailed view of compliance details to pinpoint clusters, namespaces, nodes, or deployments namespaces that do not comply with specific standards and controls.
Network Segmentation
Visualizes allowed vs. active traffic between namespaces, deployments, and pods, including external exposures.
Simulates network policy changes before they are implemented to minimize operational risk to the environment.
Risk Profiling
Heuristically ranks your running deployments according to their overall security risk by combining security-relevant data such as vulnerabilities, configuration policy violations, and runtime activity.
Tracks improvements in the security posture of your Kubernetes deployments to validate the impact of your security team actions.
Configuration Management
Delivers prebuilt DevOps and security policies to identify configuration violations related to network exposures, privileged containers, processes running as root, and compliance with industry standards.
Analyzes Kubernetes role-based access control (RBAC) settings to determine user or service account privileges and misconfigurations. Tracks secrets and detects which deployments use the secrets to limit access.
Runtime Detection and Response
Monitors system-level events within containers to detect anomalous activity indicative of a threat with the automated response using Kubernetes-native controls.
Baselines process activity in containers to automatically whitelist processes, eliminating the need to manually whitelist workloads
Uses prebuilt policies to detect crypto mining, privilege escalation, and various exploits.
A 60-day cloud service trial for Red Hat® Advanced Cluster Security cloud service is available. Please click on the link below for the Free Trial:
If you are a currently Red Hat OpenShift Service on AWS customer, an additional discount is available.
It may take time until this offer will be available to provision in console.redhat.com
Highlights
Supply Chain Security - Simplify DevOps processes by providing developers with security context in their existing workflows. Integrate security into your CI/CD pipelines and image registries to provide continuous image scanning, attestation, and assurance. Scan images for both operating system (OS) and language-level vulnerabilities.
Platform Security - Harden your organization's environment to ensure the underlying infrastructure is configured to maintain security. Prevent configuration drift using compliance checks against industry standards (CIS, NIST, HIPAA, PCI) or custom policies.
Workload Security - Prevent high-risk workloads from being deployed or run using out-of-the-box deploy-time and runtime policies. Harden workloads by enforcing zero-trust network policies that adhere to the principle of least privilege.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
This managed cloud service uses one usage-based pricing dimension. You pay by the vCPU, billed hourly on an on-demand basis. Your cost scales directly with how many vCPUs your protected workloads consume across the hours they run. There is no upfront commitment, so charges rise and fall with actual usage. As you add or remove vCPU capacity for securing your Kubernetes-based containers, billing adjusts accordingly. This single metered model keeps pricing tied to consumption rather than fixed seats or terms.
Top-of-mind questions for buyers
What counts as one vCPU for billing this cloud service?
A vCPU is a virtual processing unit used by your secured Kubernetes workloads. The service meters the vCPUs consumed by the containers and nodes it protects. Each vCPU running in a given hour counts toward your bill. More vCPUs across your clusters means more units billed.
Am I charged for vCPUs when my clusters are idle or scaled down?
Charges apply per vCPU per hour of running time. When you scale down or remove vCPU capacity, those units stop accruing software charges. Billing tracks actual consumption each hour, so costs drop when fewer vCPUs run and rise when you add capacity.
Is this pay-as-you-go, or do I commit to a term upfront?
This is pay-as-you-go. The service meters vCPU usage hourly with no upfront commitment or fixed term. Charges apply only for the vCPU-hours you actually consume. This suits variable Kubernetes workloads where cluster capacity changes over time rather than fixed, continuous usage.
www.redhat.com
Helpful?
Vendor refund policy
All fees are non-refundable
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
For the EMEA regions, Red Hat Advanced Cluster Security for Kubernetes Cloud Service offers a trusted, Kubernetes-native security solution that integrates into your hybrid cloud environments, providing a consistent and comprehensive approach to security. By embedding security across build, deploy, and runtime workflows, it empowers organizations with efficient vulnerability management, clear policy guardrails, and proactive threat detection. This Kubernetes-native approach promotes collaboration between development and platform teams, enabling faster remediation and more streamlined processes. With Red Hat Advanced Cluster Security, you can confidently scale and innovate across hybrid and multi-cloud environments while maintaining robust protection and operational efficiency tailored for modern, containerized applications.
For a free trial, head to redhat.com/acstrial
For North America and regions outside EMEA, Red Hat® OpenShift® Platform Plus builds on the capabilities of enterprise Kubernetes platform Red Hat OpenShift with advanced multi-cluster security features, day-2 management capabilities, integrated data management, and a global container registry-to protect, manage, and provide security for applications in a consistent way throughout the software life cycle across clusters.
For North America and regions outside EMEA, Red Hat® OpenShift® Platform Plus builds on the capabilities of enterprise Kubernetes platform Red Hat OpenShift with advanced multicluster security features, day-2 management capabilities, integrated data management, and a global container registry-to protect, manage, and provide security for applications in a consistent way throughout the software life cycle across clusters.
For North America and regions outside EMEA. Red Hat® OpenShift® Platform Plus for ROSA builds on the capabilities of Red Hat OpenShift Service on AWS (ROSA) with advanced multicluster security features, day-2 management capabilities, integrated data management, and a global container registry to protect, manage, and provide security for applications in a consistent way throughout the software life cycle across clusters.
One of the leading things that led us to chose Stackrox is that it is designed for Kubernetes compared to other product where containers and kubernetes feel like an add-on
What do you dislike about the product?
When I deployed stackrox, there deployment used a combination of bash scripts, raw yaml, and helm charts. While the deployment was easy, I would have preferred something that only used Helm.
What problems is the product solving and how is that benefiting you?
Ever since we started using Kubernetes, we needed a tool that would give us insights into what was happening in our clusters from a security standpoint. Stackrox provided us with the insights we wanted in addition to a lot of other information we didn't even know we wanted.
Cristian Z.
Compliance, visibility, and vulnerability management for k8s. Great tool for SOC-2 compliance.
Reviewed on Jun 08, 2020
Review provided by G2
What do you like best about the product?
StackRox has simplified compliance for us. We get a view in one place of how well we’re meeting the controls from CIS Benchmarks, NIST, PCI, and HIPAA and SOC-2. We really needed something for SOC-2 compliance, vulnerability management, IDS, k8s secrets issues, auditing access to customer environments, etc. StackRox ... rocks for this. Filling in vendor security assessments became much easier after we deployed StackRox.
What do you dislike about the product?
As a command line person, I would have preferred to have more functionality in the command line tool, but I still have to explore that a bit more.
What problems is the product solving and how is that benefiting you?
filling in security vendor assessments (we're a security company) and automatically generating compliance reports from the dashboard for SOC-2 compliance.
Andre M.
Enhanced visibility into our container vulnerabilities
Reviewed on May 08, 2020
Review provided by G2
What do you like best about the product?
Stackrox has provided us the ability to scan thousands of deployments to surface risky configuration details, detect which CVEs our images are impacted by, and alert on any unapproved image details we deem unfit for production. These advancements in visibility have given us the ability to make more informed decisions, keep up with our growing scale, and respond quickly to risky changes.
What do you dislike about the product?
Lacking strong network profile enforcement rules
What problems is the product solving and how is that benefiting you?
Prior to Stackrox, we had little visibility into vulnerabilities in our k8s environment even with the native tools
Financial Services
Compliance, visibility, and vulnerability management for k8s and containers
Reviewed on Apr 27, 2020
Review provided by G2
What do you like best about the product?
Deep integrations with Kubernetes means we understand our environment and its risks a lot better
What do you dislike about the product?
Some pre-defined policies didn't work out of the box
What problems is the product solving and how is that benefiting you?
StackRox made it easy for us to get visibility and control of our container and Kubernetes environments
Financial Services
Lightweight tool to fulfil our compliance and vulnerability management requirements
Reviewed on Apr 27, 2020
Review provided by G2
What do you like best about the product?
StackRox’s feature to automatically compare our k8s setup against best practice and its capability to monitor the system on an ongoing basis is extremely valuable to us. The system helps us to fulfil our security compliance requirements. At the same time StackRox is light weight and minimal intrusive.
What do you dislike about the product?
We don't have any complaints at the moment.
What problems is the product solving and how is that benefiting you?
Security Compliance and Vulnerability Management: It gives us insights out of the box, with preconfigured catalog of requirements and best practices.