Kubernetes Gateway API with security policies (sponsored)
Stefan Dietiker
Andreas Gruhler
16:05 - 16:20
La Cave
Moving a WAF off a virtual machine and into Kubernetes sounds straightforward until the data is highly sensitive and compliance requirements are strict. This is a field report from HIN (Health Info Net AG), the Swiss standard for secure communication in healthcare. The old setup was a single WAF virtual machine carrying a few hundred virtual hosts, with no hot reload and a proprietary config API not compatible with Kubernetes Gateway API. We share the requirements HIN defined, why Airlock Microgateway was selected, and what the architecture looks like once the WAF runs inside the cluster. The second half is about the migration itself and the decisions that made it work. Presented by Stefan Dietiker and Andreas Gruhler.
