Aviatrix
Cloud Native Security Fabric Architecture Overview
Pages
11
Time to read
16 mins
Publication
Language
English
Pages
11
Time to read
16 mins
Publication
Language
English
This document is a whitepaper that outlines the Cloud Native Security Fabric (CNSF) as a solution to the challenges posed by the Architectural Divide in cloud security. It describes the need for a containment platform that enforces security at every workload, operates across various compute models without requiring agents, and propagates a single policy rapidly. The paper defines containment rigorously, emphasizing the importance of architectural enforcement of communication policies that govern interactions at the workload level. It presents five testable properties that any architecture must demonstrate to deliver effective containment: path-completeness, identity-awareness at Layer 7, detection-independence, compute-model agnosticism, and universal propagation. The document further explains how CNSF addresses existing gaps in security architecture, such as fragmentation, runtime enforcement, and ownership, by providing a unified control plane that adapts to changes in infrastructure automatically. CNSF is positioned as a foundational security architecture that is essential for modern cloud environments, particularly for securing AI workloads.