Agent Working Group

Mission Statement

The Open Horizon project's Agent Working Group exists to facilitate use and development of the Open Horizon platform by collaborating with all interested parties to enhance the capabilities and features of the Open Horizon agent to meet new and emerging use cases

Leadership

Working Group Chair: @Doug Larson 

Mailing List

Discussion Forum

Meeting Time

  • Agent Meetings are open to the public, and are held bi-weekly, starting July 27th 2020.

  • Agent Working Group meetings are held every other Monday at 8:30am PT (find your local time here)

---- 

LF Edge Working Group 2 is inviting you to a scheduled Zoom meeting.

Topic: Open Horizon Agent WG Meeting
Time: Oct 5, 2020 08:30 AM Pacific Time (US and Canada)
Every 2 weeks on Mon, until Dec 11, 2023

Please download and import the following iCalendar (.ics) files to your calendar system.
Weekly: https://zoom.us/meeting/tJAkf-mvqT4jEtGjQRlTcROfQH_K8nJW8sNA/ics?icsToken=98tyKuCspzMqHdOQuRGCRowIHYqgc-3wtiVEj7d6li7XDxRQUCzwB8p9GepxOu-I

Join Zoom Meeting
https://zoom.us/j/94980775985?pwd=clk0bFhwVU5SNVFLa1JUWHZZNTRDQT09

Meeting ID: 949 8077 5985
Passcode: 177315
One tap mobile
+13462487799,,94980775985# US (Houston)
+16699006833,,94980775985# US (San Jose)

Dial by your location
+1 346 248 7799 US (Houston)
+1 669 900 6833 US (San Jose)
+1 253 215 8782 US (Tacoma)
+1 312 626 6799 US (Chicago)
+1 929 205 6099 US (New York)
+1 301 715 8592 US (Germantown)
888 788 0099 US Toll-free
877 853 5247 US Toll-free
Meeting ID: 949 8077 5985
Find your local number: https://zoom.us/u/av0XQgb3W




Working Group Meeting Minutes

2023

2022

2021

2020

Sub-groups

2023

AccuKnox has proposed an Isolation-centric workstream.  A sub-group has been formed and meets Wednesdays at 12 noon ET/9am PT.

  • Initial meeting 2023-07-26, recording: 35 minutes

  • Discussed options, capabilities, and eventually actionable goals. AccuKnox will create a Feature Candidate proposal containing our notes from the meeting.

    Ideas:

    1. If an attack is in progress or there is some other security policy violation, how should that information be surfaced from KubeArmor to Open Horizon? What should OH do about it? Should we extend the deployment policy to allow constraints to address and potentially terminate the agreement?

    2. How should OH/IEAM integrate with KubeArmor and Discovery Engine? DE includes thresholds and targets for notifications, as well as automated security policy generation.

    3. How do we address Day 1 deployment of KubeArmor? Only use their containerized version and deploy that way? Or extend our agent installation script to allow installing systems version of KubeArmor?

    4. How should OH facilitate KubeArmor control plane messaging through anax?


2022

AccuKnox presented a proposal to the TSC for a series of POCs solving security use cases.  We've formed a 2022 sub-group to evaluate those.

POC Zero:

  • Target environment is x86-based hosts, device agent

  • Goal is to observe/audit Agent interactions, generate policy based on those interactions, and enforce the policy

  • Services will be deployed during observation and enforcement but not observed

POC One:

  • Target environment is x86-based hosts, device agent

  • Goal is to observe/audit Docker-based applications and their interactions, generate policy based on those interactions, and enforce the policy

2022 Meeting:


Documents

  • TBA