| ID | Title | Description | Threat Mappings |
|---|---|---|---|
| CCC.ContOrch.F07 | Storage Integration | Supports attaching ephemeral or persistent storage volumes to running containers in the Kubernetes cluster. | 0 |
| CCC.ContOrch.F09 | Cluster Auto Scaling | Ability to automatically scale the number of worker nodes in the cluster based on workload demand, ensuring efficient resource utilization. | 0 |
| CCC.K8S.F01 | Managed Kubernetes Control Plane | Provides a fully managed Kubernetes control plane that has high availability, with automatic updates and patching. | 0 |
| CCC.K8S.F02 | Managed Node Pool | Provides fully managed Kubernetes worker nodes (compute resources). These nodes are provisioned, updated, patched, and monitored for you by the service. | 0 |
| CCC.K8S.F03 | Virtual Nodes | Ability to have fully managed virtual compute resources to power Kubernetes worker nodes. This will eliminate the need to manage underlying nodes. | 0 |
| CCC.K8S.F04 | GPU Support | Support for GPU-accelerated workloads through integration of GPUs, enabling high-performance computing. | 0 |
| CCC.K8S.F05 | OCI Container Image Execution | Supports running containerized workloads using OCI-compliant images, providing an isolated execution environment for applications. | 0 |
| CCC.K8S.F06 | Container Registry Integration | Enables integration with public or private container registries to retrieve container images for execution. | 0 |
| CCC.K8S.F08 | Built-in Ingress Load Balancing | Built-in support for distributes incoming traffic across running container instances to optimize resource usage and availability. | 0 |
| CCC.K8S.F10 | Private Cluster Endpoints | Ability to restrict access to the Kubernetes API server to private networks, ensuring the control plane is only accessible within your VPC. | 0 |
| CCC.K8S.F11 | Service Mesh Integration | Ability to integrate with managed service mesh offering by the cloud service provider for service discovery, traffic routing, observability, and security. | 0 |
| CCC.K8S.F12 | Secrets Integration | Ability to seamlessly integrate with cloud native secret manager service to securely manage and access secrets, such as API keys, database credentials, or certificates, within Kubernetes workloads. | 0 |
| CCC.K8S.F13 | Observability Tooling Integration | Ability integrate with Observability tooling such as Prometheus and Grafana to provide comprehensive monitoring, and visualization for Kubernetes clusters. | 0 |
Imports
| ID | Remarks |
|---|---|
| CCC.Core.CP01 | Encryption in Transit Enabled by Default |
| CCC.Core.CP02 | Encryption at Rest Enabled by Default |
| CCC.Core.CP06 | Access Control |
| CCC.Core.CP14 | API Access |
| CCC.Core.CP19 | Child Resource Scaling |
| CCC.Core.CP22 | Location Lock-In |
| CCC.Core.CP23 | Network Access Rules |
| CCC.Core.CP24 | Core Processing Units |
| CCC.Core.CP25 | Random Access Memory Allocation |
| CCC.Core.CP26 | Persistent Storage |
| CCC.Core.CP27 | Configurable Network Ports |
| CCC.Core.CP28 | Command-line Interface |
| CCC.Core.CP29 | Active Ingestion |
| CCC.Core.CP30 | Passive Ingestion |