Make the Secure Kubernetes Supply Chain Work for You - Adolfo García Veytia, Chainguard

less than 1 minute read

Abstract

Starting in Kubernetes 1.22, SIG Release started building new security features into Kubernetes releases to make the project a better citizen in the software supply chain. The push to secure the release process has produced tools and processes that have improved the way other projects in the ecosystem are released. At the same time, we have made sure that Kubernetes plays well in the wider chain: verifying what we get from upstream and making sure consumers of our artifacts can trust what they get from us. This talk will give an overview of lessons learned and tools we have created that you can reuse in your own projects to secure your releases. It will center around three key moments and technologies: The initial effort involved producing SBOMs to describe sources and artifacts along with their dependencies. Then, we’ll understand the provenance attestations that make the release process SLSA compliant. Finally, we’ll see how digital signatures are implemented in the project.Click here to view captioning/translation in the MeetingPlay platform!

Sched URL

Video