Runtime security, stronger isolation, Trino public or private
You see what your containers really do, and isolation between organizations no longer rests on our code alone.
- A security agent runs on every node. It watches what containers actually do, and every alert names the organization it concerns.
- All the alerts are in one place. A page in the control center gathers the security alerts of the whole fleet.
- Isolation moves into Kubernetes. A request that tried to bypass the platform is refused by the Kubernetes API itself, no longer by our code alone.
- You choose whether Trino is exposed. A Data Dock's Trino is public or private, and you switch it in one click from the console.
- The network is closed by default. Access to Trino, to pipelines and to managed
PostgreSQLdatabases is protected without you writing a rule. - You choose your vulnerability databases. The ones image scanning uses, including on an installation with no internet access.
- Third-party images are configurable. You point them at your own registry from the installation chart.