Prisma Cloud supports any environment, including both Tanzu Application Service (TAS) and Tanzu Kubernetes Grid (TKGI). Prisma Cloud automatically scales up and down in concert with your environment and applications.
The solution consists of two components: Console and Defender.
Console serves both the user interface and API, which let you define policy, configure and control your deployment, and view the overall health, from a security perspective, of your cloud-native environment. Palo Alto Networks can run Console for you as a SaaS service, or you can run and operate it yourself.
Defenders are deployed to each node in your cluster. They collect security data and enforce policies. In TAS, Defenders are deployed to each Diego cell as a BOSH add-on. In TGKI, Defenders are deployed to each worker node as a DaemonSet.
With Defenders deployed, you get immediate visibility into the vulnerabilities and compliance issues for the apps and hosts in your clusters. Defenders automatically create allowlist models to protect apps at runtime. Configure Defenders to scan your blobstores and registries to validate that images meet your security bar before they run.