Service Mesh Academy

FedRAMP and Kubernetes: Practical Lessons Learned

March 6, 2025

Companies that sell SaaS products to the US federal market frequently face the challenge of attaining FedRAMP authorization to operate, a critical compliance requirement for government buyers. The use of Kubernetes can both simplify and compound this challenge. On one hand, the use of containerization; the dynamic nature of orchestration; the mutability of network identity; and other technical characteristics of Kubernetes can be difficult to map to compliance controls that were created without these systems in mind. On the other hand, Kubernetes can actually make some aspects of FedRAMP authorization, such as FIPS-validated encryption of data in transit, easier to achieve.

In this webinar, Zscaler Principal Software Engineer John Hamilton joined Buoyant CEO William Morgan to discuss how Zscaler successfully navigated the FedRAMP process on its Kubernetes platform. The conversation covers everything from meeting the technical requirements to running the process to interacting with other parts of the organization and with auditors directly. John shares his stories about the steps, challenges, and critical elements that anyone trying to achieve FedRAMP authorization with Kubernetes will need to know.

The conversation is practical in focus and appropriate for both technical and non-technical audiences.