Okay, I've been living in the Cloud One console for a few months now, mostly for the Container and File Storage Security modules. The new Workload Security module popped up last week, and I'm trying to wrap my head around where it fits.
It feels like a direct evolution from Deep Security, but "cloud-native-ified." The agentless approach for AWS EC2 is what caught my eye first. Spun up a test instance without the traditional DS Agent, and the visibility was surprisingly detailed—vulnerability assessment, log inspection, the works. But I'm immediately wondering about the cost model shift. With agentless, are we looking at a pure per-instance, per-hour consumption cost? How does that compare, long-term, to the older agent-based licensing for a fleet of stable, long-running workloads?
Also, the integration with the rest of the Cloud One platform seems... almost too seamless? I'm seeing events from Workload Security flowing into the same Cloud One Conformity and Application Security consoles. This is powerful for a unified risk view, but I'm curious about the practical setup. Has anyone mapped out a real-world policy migration path from an on-prem Deep Security Manager deployment to this? I'm particularly fuzzy on how custom firewall rules or specific compliance templates translate.
And a pointed follow-up: the documentation mentions "optimized for DevOps workflows." Does that mean native Terraform provider support for all the security policies, or is it more about the API? I need to codify everything, and the depth of the API coverage will make or break this for my team.