<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Compliance on Kubernetes: PCI DSS, GDPR, DORA, CIS on Cozystack</title><link>https://deploy-preview-660--cozystack.netlify.app/compliance/</link><description>Recent content in Compliance on Kubernetes: PCI DSS, GDPR, DORA, CIS on Cozystack</description><generator>Hugo</generator><language>en</language><atom:link href="https://deploy-preview-660--cozystack.netlify.app/compliance/index.xml" rel="self" type="application/rss+xml"/><item><title>PCI DSS Compliance on Kubernetes with Cozystack</title><link>https://deploy-preview-660--cozystack.netlify.app/compliance/pci-dss/</link><pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate><guid>https://deploy-preview-660--cozystack.netlify.app/compliance/pci-dss/</guid><description>&lt;p&gt;&lt;strong&gt;Cozystack provides most of the technical controls a PCI DSS 4.0.1 assessment depends on,
and several of them are active on a fresh install.&lt;/strong&gt; It is an open-source cloud platform built
on Kubernetes, KubeVirt and Talos Linux that runs on your own bare metal. Tenant network
isolation, privilege restrictions on workloads, automatic TLS for published services and
encrypted backups need no configuration at all.&lt;/p&gt;
&lt;p&gt;Others are shipped but not switched on, because most clusters do not need them: single
sign-on, volume encryption, restricted egress, encrypted east-west traffic, longer audit
retention. Each is a configuration option rather than a development project, and this page
says which is which, requirement by requirement — along with the parts an assessment leaves
to you, so none of them surprise you late.&lt;/p&gt;</description></item><item><title>GDPR Compliance on Kubernetes with Cozystack</title><link>https://deploy-preview-660--cozystack.netlify.app/compliance/gdpr/</link><pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate><guid>https://deploy-preview-660--cozystack.netlify.app/compliance/gdpr/</guid><description>&lt;p&gt;&lt;strong&gt;Personal data on Cozystack stays where you put it.&lt;/strong&gt; The platform is open-source software
built on Kubernetes, KubeVirt and Talos Linux that runs on your own hardware: no control plane
in someone else&amp;rsquo;s cloud, no vendor account, no service to sign up for. On top of that it
brings the measures Article 32 asks about — encryption in transit and for backups, centralized
identity, tenant isolation enforced by network policy, audit logging, backup and restore.&lt;/p&gt;</description></item><item><title>CIS Kubernetes Benchmark Results on Cozystack and Talos</title><link>https://deploy-preview-660--cozystack.netlify.app/compliance/cis-benchmark/</link><pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate><guid>https://deploy-preview-660--cozystack.netlify.app/compliance/cis-benchmark/</guid><description>&lt;p&gt;&lt;strong&gt;Cozystack starts from a hardened position, and the numbers say so: 54 CIS controls pass on
a cluster nobody tuned for the test.&lt;/strong&gt; The node operating system is immutable and has no
shell, privileged workloads are refused by admission, every etcd control passes, and tenants
come with network isolation already applied.&lt;/p&gt;
&lt;p&gt;This page publishes the full run rather than the flattering part of it. A raw kube-bench
report also lists two dozen failures, and the useful work is telling them apart: most are the
benchmark looking for files an immutable node does not keep, or testing a flag that newer
Kubernetes releases replaced. Four are worth your attention, and each is covered below with
the reasoning behind it.&lt;/p&gt;</description></item><item><title>DORA on Kubernetes: ICT Third-Party Risk and Resilience</title><link>https://deploy-preview-660--cozystack.netlify.app/compliance/dora/</link><pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate><guid>https://deploy-preview-660--cozystack.netlify.app/compliance/dora/</guid><description>&lt;p&gt;&lt;strong&gt;For the chapter of DORA that decides most platform conversations — dependence on a single
ICT provider — Cozystack is about as good an answer as infrastructure gets.&lt;/strong&gt; It is
open-source software under Apache 2.0, it runs on your own hardware, and leaving it means
moving standard Kubernetes objects and virtual machines rather than unwinding a proprietary
format. An exit strategy you can rehearse beats a clause promising cooperation.&lt;/p&gt;
&lt;p&gt;The resilience side is solid too: replicated storage across nodes, live migration between
them, declared state that the platform continuously restores, multi-datacenter topologies as
a normal deployment shape, backups encrypted by default. This page goes through all of it,
and marks the handful of places where you need to configure something rather than inherit it.&lt;/p&gt;</description></item><item><title>Kubernetes Conformance Results for Cozystack</title><link>https://deploy-preview-660--cozystack.netlify.app/compliance/kubernetes-conformance/</link><pubDate>Wed, 19 Aug 2026 00:00:00 +0000</pubDate><guid>https://deploy-preview-660--cozystack.netlify.app/compliance/kubernetes-conformance/</guid><description>&lt;p&gt;&lt;strong&gt;Kubernetes clusters created by Cozystack pass the CNCF conformance suite in full.&lt;/strong&gt; The
suite answers one narrow question, and it is the question every evaluation starts with: is
this real Kubernetes, or something Kubernetes-shaped? A conformant cluster runs standard
manifests, Helm charts and operators without a vendor dialect.&lt;/p&gt;
&lt;p&gt;Two independent sets of results are recorded below, from the two shapes the platform is used
in — a cluster you run yourself, and a hosted platform built on it. Between them they cover
every Kubernetes release the platform offers.&lt;/p&gt;</description></item></channel></rss>