Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
The Knox API Gateway functions as a reverse proxy, prioritizing flexibility in policy enforcement and backend service management for the requests it handles. It encompasses various aspects of policy enforcement, including authentication, federation, authorization, auditing, dispatch, host mapping, and content rewriting rules. A chain of providers, specified in the topology deployment descriptor associated with each Apache Hadoop cluster secured by Knox, facilitates this policy enforcement. Additionally, the cluster definition within the descriptor helps the Knox Gateway understand the structure of the cluster, enabling effective routing and translation from user-facing URLs to the internal workings of the cluster. Each secured Apache Hadoop cluster is equipped with its own REST APIs, consolidated under a unique application context path. Consequently, the Knox Gateway can safeguard numerous clusters while offering REST API consumers a unified endpoint for seamless access. This design enhances both security and usability by simplifying interactions with multiple backend services.
Description
Knox serves as a secret management platform designed for the secure storage and rotation of sensitive information such as secrets, keys, and passwords utilized by various services. Within Pinterest, a multitude of keys and secrets are employed for diverse functions, including signing cookies, encrypting sensitive data, securing the network through TLS, accessing AWS machines, and facilitating communication with third-party services, among others. The risk of these keys being compromised posed significant challenges, as the process of rotation typically required a deployment and often necessitated changes to the codebase. Previously, keys and secrets at Pinterest were stored in Git repositories, leading to their replication across the company's infrastructure and presence on numerous employee laptops, which made tracking access and auditing who had permission to use these keys virtually impossible. To address these issues, Knox was developed with the intention of simplifying the process for developers to securely access and utilize confidential secrets, keys, and credentials. It also ensures the confidentiality of these sensitive elements while providing robust mechanisms for key rotation in the event of a security breach, thereby enhancing overall security practices. By implementing Knox, Pinterest aims to streamline secret management processes while fortifying its defenses against potential vulnerabilities.
API Access
Has API
Yes
API Access
Has API
Yes
Integrations
Apache Flink
Yes
Apache HBase
Yes
Apache Hadoop YARN
Yes
Apache Hive
Yes
Apache Ranger
Yes
Apache Solr
Yes
Apache Storm
Yes
Cloudera
Yes
Docker
No
Hadoop
Yes
Integrations
Apache Flink
No
Apache HBase
No
Apache Hadoop YARN
No
Apache Hive
No
Apache Ranger
No
Apache Solr
No
Apache Storm
No
Cloudera
No
Docker
Yes
Hadoop
No
Pricing Details
No price information available.
Free Trial
No
Free Version
No
Pricing Details
No price information available.
Free Trial
No
Free Version
Yes
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Vendor Details
Company Name
Apache Software Foundation
Founded
1999
Country
United States
Website
knox.apache.org
Vendor Details
Company Name
Founded
2009
Country
United States
Website
github.com/pinterest/knox
Product Features
API Management
API Design
No
API Lifecycle Management
No
Access Control
No
Analytics
No
Dashboard
No
Developer Portal
No
Testing Management
No
Threat Protection
No
Traffic Control
No
Version Control
No
Product Features
Privileged Access Management
Application Access Control
No
Behavioral Analytics
No
Credential Management
No
Endpoint Management
No
For MSPs
No
Granular Access Controls
No
Least Privilege
No
Multifactor Authentication
No
Password Management
No
Policy Management
No
Remote Access Management
No
Threat Intelligence
No
User Activity Monitoring
No