The shift to 5G Standalone (5G SA) represents a fundamental architectural change in telecommunications, moving from monolithic, hardware-centric systems to a highly distributed, cloud-native architecture. While this disaggregation offers agility, flexibility, and scalability, it simultaneously introduces a massive new attack surface. Securing this environment is paramount, particularly given the critical nature of telco networks as … Continued
The post Implementing Proactive Security and Governance for Telco Networks using VMware Telco Cloud Platform appeared first on VMware Telco Cloud Blog.
The shift to 5G Standalone (5G SA) represents a fundamental architectural change in telecommunications, moving from monolithic, hardware-centric systems to a highly distributed, cloud-native architecture. While this disaggregation offers agility, flexibility, and scalability, it simultaneously introduces a massive new attack surface. Securing this environment is paramount, particularly given the critical nature of telco networks as national infrastructure and the stringent compliance requirements imposed by regulatory bodies worldwide.
In this complex, cloud-native domain, the 5G Core manages thousands of distributed Cloud-native Network Functions (CNFs). To effectively secure such an environment, the mandate is clear: we must enforce consistent, granular security policies across every site, cluster, and CNF. This is the gold standard of security that modern telco platforms must achieve.
VMware Telco Cloud Platform leverages its Kubernetes Policy Manager to meet this gold standard of security along with the security governance standards and hardening recommendations established by the NSA and CISA. Kubernetes Policy Manager makes use of Open Policy Agent (OPA) and Gatekeeper to provide a standardized framework for policy-driven orchestration and governance.

Figure 1: Kubernetes Policy Manager
Open Policy Agent (OPA): The Policy Service
OPA acts as the universal policy engine. Its primary role is to interpret and evaluate sophisticated, telco-grade security rules written in Rego. Rego is a high-level, declarative policy language specifically designed for OPA. Rego allows security teams to express complex constraints—from image security and network policies to resource limits and configuration best practices—in a clear, auditable format. OPA decouples policy logic from the enforcement point, making policies highly reusable across various systems, whether Kubernetes, service meshes, or APIs.
Gatekeeper: The Enforcement Mechanism
Gatekeeper tightly integrates OPA into the Kubernetes ecosystem. It functions as a Kubernetes Admission Controller, intercepting all requests made to the Kubernetes API server—specifically CREATE, UPDATE, and DELETE operations. By sitting in the admission control path, Gatekeeper uses the policies defined in OPA to decide whether an incoming configuration is compliant. If the configuration violates a policy, Gatekeeper rejects the request proactively, preventing the insecure configuration from ever reaching the cluster state. Such violations are termed as Admission-time Violations and an alert is raised for such violations by Kubernetes Policy Manager.
The Kubernetes Policy Manager also tracks CNFs deployed before policy enforcement that are found to violate security constraints. These types of violations are termed Audit-time Violations. These violating CNFs are not immediately evicted. However, while the security violation persists, the Kubernetes Policy Manager prevents any subsequent Lifecycle Management (LCM) operations from being performed on them.
Kubernetes Policy Manager translates the enforced security policies into standard Kubernetes constructs, which are then applied to the CaaS clusters. This translation results in the creation of two types of Kubernetes Custom Resources (CRs): Constraint Templates and Constraints.

Figure 2: Kubernetes Custom Resources
Using this robust setup, the Kubernetes Policy Manager provides continuous and comprehensive security guardrails:
Now let’s run through the steps for implementing and testing the capabilities of Kubernetes Policy Manager:
Deploy OPA



Enforce Policies



Test OPA in action




By leveraging the Kubernetes Policy Manager in VMware Telco Cloud Platform, organizations can shift their security posture to proactive governance. This approach reduces the potential for human error, automates compliance checks, and ensures that 5G infrastructure is secure by design from the outset. With the Kubernetes Policy Manager integrated into the Telco Cloud Platform, service providers are empowered to manage a secure, sovereign telco cloud environment reliably and at massive scale. This capability is essential for meeting stringent regulatory requirements and maintaining high service availability.
Subscribe to get the latest posts sent to your email.