Cloud Native
Security Talks
RSS

CloudNativeSecurityCon Europe 2022

Protect the Pipe! A Policy-based Approach for Securing CI/CD Pipelines

Shripad Nadgowda, IBM Research & Jim Bugwadia, Nirmata

Abstract

Modern applications are composed of hundreds of packages and delivered to production via automated CI/CD pipelines. With rapid delivery comes the growing risk of attacks, vulnerabilities, and misconfigurations. Protecting these critical assets requires policy-based controls for CI/CD pipeline composition, configurations and execution. In this session, Shripad and Jim will present a cloud-native security framework for Tekton pipelines using in-toto, Kyverno and sigstore. They will discuss the unique security challenges for CI/CD pipelines, and then demonstrate the use of open-source tools to attest and verify each pipeline resource and execution step using declarative policies.Click here to view captioning/translation in the MeetingPlay platform!

More from CloudNativeSecurityCon Europe 2022

Open in the index →
  1. VEX! or... How to Reduce CVE Noise With One Simple Trick!Frederick Kautz 2022-05-16
  2. Using CNCF Best Practices for Software Supply Chain to Guide and Enhance Your Security PostureRyan Gibbons, 3m & Conor Rogers, Stelligent 2022-05-16
  3. The Unexpected Demise of Open Source LibrariesLiran Tal, Synk 2022-05-16
  4. TUF Maintainer Panel DiscussionAndrew Krug, Datadog; Asra Ali, Google; Marina Moore, NYU; Trishank Karthik Kuppusamy, Datadog; & Jussi Kukkonen, VMware 2022-05-16
  5. Security Champions: The What, Why, and HowAnn Marie Fred, Red Hat 2022-05-16
  6. Fuzzing the CNCF LandscapeAdam Korczynski & David Korczynski, Ada Logics 2022-05-16
  7. Dissecting the Discovery of the 0-Day Supply Chain Vulnerability in Argo CDMoshe Zioni, Apiiro 2022-05-16
  8. CTF Overview and ExperienceLewis Denham-Parry, Control Plane 2022-05-16
  9. Vanquishing Vulnerabilities in ValenciaAlba Ferri Fitó, Sysdig & Eric Smalling, Synk 2022-05-17
  10. Towards the Hardened Cloud-Native Cornerstone: Container Runtime Protection from Security to PrivacyKailun Qin, Intel 2022-05-17
  11. Top 5 Reasons (and 5 Myths Debunked) to Invest in Securing the Software Supply ChainHector Linares, Microsoft 2022-05-17
  12. Shrinking Software Attack Surface with WebAssembly & CNCF WasmcloudLiam Randall, Cosmonic 2022-05-17
  13. Securing the Supply Chain with WitnessCole Kennedy, TestifySec 2022-05-17
  14. Real Time Security - eBPF for Preventing attacksLiz Rice, Isovalent 2022-05-17
  15. Putting the Supply Chain Pieces together: A Deep Dive into the Secure software FactoryMichael Lieberman, Citi 2022-05-17
  16. Purple Teaming Like Sky’s the Limit – Adversary Emulation in the Cloud with Stratus Red TeamChristophe Tafani-Dereeper, Datadog 2022-05-17
  17. Deep Dive: Serverless Security (STAG Presentation)Andrew J Krug, Datadog; Ragashree M C, Nokia; Ashish Rajan, CISO & Ariel Shuper, Cisco 2022-05-17