Updated on 2024-04-15 GMT+08:00

Enabling Container Security Protection

You can enable the container security edition for your containers.

To enable protection for a container node, you need to allocate a quota to the node. If the protection is disabled or the node is deleted, the quota can be allocated to another node.

Check Frequency

HSS performs a full check in the early morning every day.

After you enable server protection, you can view scan results after the automatic scan in the next early morning.

Constraints

Currently, HSS can only protect Docker containers.

Prerequisite

  • The Agent Status of a server is Online. To check the status, choose Host Security Service > Asset Management > Containers & Quota.
  • You have created a node on CCE.
  • The Protection Status of the node is Unprotected.

Procedure

  1. Log in to the management console.
  2. In the upper left corner of the page, click , select a region, and choose Security > Host Security Service.
  3. In the navigation pane, choose Asset Management > Containers & Quota.
  4. Enable protection for one or multiple servers.

    • Enabling protection for a server
      1. In the Operation column of a server, click Enable Protection.
      2. In the dialog box that is displayed, confirm the information.

        A container security quota protects one cluster node.

      3. Confirm the information and click OK. If the Protection Status in the container list changes to Protected, it indicates the protection has been enabled.
    • Enabling protection in batches
      1. In the node list, select servers, and click Enable Protection above the list.
      2. In the dialog box that is displayed, confirm the information.

        A container security quota protects one cluster node.

      3. Confirm the information and click OK. If the Protection Status in the container list changes to Protected, it indicates the protection has been enabled.