Migrating Existing EKS Clusters to EKS Auto Mode
Read Now

Welcome to our new, ongoing blog series called Product Bytes that highlights recent product enhancements we’ve made to our Kubernetes Management Cloud (for enterprises) and Kubernetes Management Cloud for MSPs (for service providers) products so you can stay up to date on what’s new. In this, our first installment, we’ll introduce a number of key improvements, but stay tuned because we’ll follow up with detailed blog posts on the features worth taking a deeper dive.

One of the most exciting new features is Zero-Trust Kubectl Access (ZTKA). The ZTKA (pictured above) secures access to a managed cluster's API server via a proxy providing centralized authentication, authorization and auditing. It also provides for the instant provisioning and de-provisioning of user access. As a result, ZTKA empowers IT Ops and DevOps teams to easily access clusters via kubectl while complying with regulatory and governance requirements -- enforced via easy RBAC configuration. All access is audited and does not require inbound firewall rules. ZTKA is included in the Kubernetes Management Cloud. See our ZTKA video, read our docs or sign up for a demo to see it in action -- stay tuned for more blog posts detailing all the features of ZTKA!

Rafay has the deepest Amazon EKS integration on the market and, with our latest release, it just got deeper. In addition to on-demand EC2 instances, Rafay can also provision worker nodes using spot instances that can provide 70-90% savings over on-demand prices. Further, Rafay-provisioned Amazon EKS Clusters are now configured as Private by default, ensuring the cluster's control plane is not visible or accessible over the Internet. And our default cluster blueprint for Rafay-provisioned Amazon EKS clusters has been updated to automatically deploy the AWS Node Termination Handler to ensure spot instance interruptions are handled gracefully. We are extremely excited about our ever-expanding partnership with Amazon (see Rafay joins AWS Outposts Ready Program) and look forward to deeper integrations and joint innovation.

We at Rafay are always adding more capabilities to our long list of cluster and fleet management features. Here is a sample of our most recent enhancements:

The Rafay workload wizard has been enhanced to leverage Rafay’s turnkey integration with Hashicorp’s Vault (pictured above) and Prometheus. With this improved integration, workload administrators can a) enable secure and dynamic retrieval of application secrets from their central Hashicorp Vault server and b) configure and enable the use of custom, application-specific metrics for horizontal pod autoscaling (HPA) in just a few clicks. For more information, check out each of these two sections in our Kubernetes Management Cloud documentation: managing secrets and integrating monitoring.
There are literally dozens of other recent additions and improvements to Rafay’s products and I encourage you to give them a spin for yourself or read our documentation for more information! As always we’d love your questions and feedback. Stay tuned for future Product Bytes detailing many of the features above!
.png)

In this blog, we will describe how Rafay Zero Trust Kubectl Access Proxy gives Argo CD a secure path to every cluster in the fleet, even when those clusters sit deep behind corporate firewalls.
Read Now

Kubernetes is a rapidly evolving open-source project with periodic releases. And organizations embracing Kubernetes must adopt the practice of regular upgrades.
Read Now