logo

Secure Amazon container workloads using container attribute-based rules in AWS Network Firewall

ID: 3bdf4b67-45c2-5dd0-b6c9-7e0809aee7cc

STIX ID: report--3bdf4b67-45c2-5dd0-b6c9-7e0809aee7cc

Feed Name: AWS Security Blog

Date Published: 2026-07-01

Date Updated: 2026-07-02

Author: Amit Gaur

...
...

**AWS Network Firewall container attribute-based rules for Amazon EKS/ECS**: The post describes how to map Kubernetes attributes (namespaces, pod names, cluster names, labels) to Network Firewall container associations and reference them in Suricata-compatible stateful rules to provide layer 7 inspection, FQDN filtering, TLS handling, and enriched logging for containerized workloads; it includes a console walkthrough, prerequisites (for example disabling SNAT), testing guidance, and considerations for performance and pod-to-pod traffic.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.