Cloud Native
Security Talks
RSS

KubeCon Europe 2023

Building SLSA 3 Conforment Attestors for Artifacts Generated on GitHub

Ian Lewis & Asra Ali, Google

Abstract

Supply chain Levels for Software Artifacts, or SLSA (salsa) is a security framework to reason about and improve the integrity of released artifacts. SLSA (slsa.dev) is seeing increased adoption, both from industry and open source projects. Besides released artifacts, SLSA provenance attestation may also be generated for other types of “artifacts”, such as vulnerability scanner results, SBOMs, etc. This allows the generation of trustworthy supply-chain metadata about arbitrary artifacts. Implementing a SLSA compliant attestor is, however, hard work, and requires expertise in both SLSA and the underlying platform used to build it. Come to this talk to learn about a recent extension of the SLSA framework that allows you to wrap existing tools (in the form of a binary, a GitHub Action or a container) into a SLSA compliant attestor, with minimal effort. We will show how SLSA builders for several package managers, such as npm and maven, are implemented with this framework. We will also report the lessons learned and the challenges we faced, in the hope it will help others in the field. At the end of this talk, attendees will have enough background to make their tool attest to their output using SLSA provenance.

More from KubeCon Europe 2023

Open in the index →
  1. Zero Privilege ArchitecturesThijs Ebbers & Diana Iordan, ING 2023-04-19
  2. Using OpenTelemetry for Application Security, with a Real Life ExampleRon Vider, Oxeye 2023-04-19
  3. The Hacker's Guide to KubernetesPatrycja Wegrzynowicz, Form3 2023-04-19
  4. From SBOMs to IBOMs - Know What's Happening in Your ClustersIdo Neeman, Firefly 2023-04-19
  5. Confidential Containers Made EasyFabiano Fidencio, Intel & Jens Freimann, Red Hat 2023-04-19
  6. Cert-Manager Can Do SPIFFE? Solving Multi-Cloud Workload Identity Using a De Facto Standard ToolThomas Meadows, Jetstack & Joshua Van Leeuwen, Diagrid 2023-04-19
  7. Anatomy of a Cloud Security Breach - 7 Deadly SinsMaya Levine, Sysdig 2023-04-19
  8. Adopting Network Policies in Highly Secure EnvironmentsRaymond de Jong, Isovalent 2023-04-19
  9. A Confidential Story of Well-Kept SecretsLukonde Mwila, AWS 2023-04-19
  10. 🦝 RBAC to the Future: Untangling Authorization in KubernetesJimmy Mesta, KSOC 2023-04-19
  11. 🦝 Canals and Bridges: Using Amsterdam’s Transit System To Secure K8s NetworksCailyn Edwards, Shopify 2023-04-19
  12. Running Not Root Made EasyLuboslav Pivarc, Red Hat 2023-04-20
  13. Rotate Roots Right Round: Using Cert-Manager for Safer Private PKIAshley Davis, Jetstack 2023-04-20
  14. Mind the Gap! Bringing Together Cloud Services and Managed K8s EnvironmentsChristophe Tafani-Dereeper, Datadog & Diego Comas, Sourcegraph 2023-04-20
  15. Kubernetes Defensive Monitoring with PrometheusDavid de Torres Huerta & Mirco De Zorzi, Sysdig 2023-04-20
  16. Improve Vulnerability Management with OCI Artifacts – It Is That Easy!Itay Shakury, Aqua Security & Toddy Mladenov , Microsoft 2023-04-20
  17. Image Signing and Runtime Verification at Scale: Datadog's JourneyEthan Lowman, Datadog 2023-04-20
  18. Cluster Grey Zone: Risks in Managed Cluster MiddlewareShay Berkovich & Barak Sharoni, Wiz 2023-04-20
  19. Checking the Chains at the Gate: Building Supply Chain Policies with Gatekeeper and RatifyJeremy Rickard, Microsoft 2023-04-20
  20. Back to the Future: Next-Generation Cloud Native SecurityMatt Jarvis, Snyk & Andrew Martin, Control Plane 2023-04-20
  21. Automated Cloud-Native Incident Response with Kubernetes and Service MeshMatt Turner, Tetrate & Francesco Beltramini, Control Plane 2023-04-20
  22. No video 🦝 Minimalism: Key to Cloud SecurityBarun Acharya, Accuknox 2023-04-20
  23. 🦝 Interactive Playground to Learn Kubernetes and Cloud Native SecurityMadhu Akula 2023-04-20
  24. 🦝 Guardians of the Runtime: Leveraging Behavioral Analysis and PoliciesBen Hirschberg, ARMO 2023-04-20
  25. What Can Go Wrong When You Trust Nobody? Threat Modeling Zero TrustJames Callaghan & Richard Featherstone, ControlPlane 2023-04-21
  26. The Next Log4jshell?! Preparing for CVEs with eBPF!Natalia Reka Ivanko & John Fastabend, Isovalent 2023-04-21
  27. Prevent Embarrassing Cluster Takeovers with This One Simple Trick!Daniele de Araujo dos Santos & Shane Lawrence, Shopify 2023-04-21
  28. Practical Challenges with Pod Security AdmissionV Körbes & Christian Schlotter, VMware 2023-04-21
  29. Malicious Compliance: Reflections on Trusting Container ScannersIan Coldwater, Independent; Duffie Cooley, Isovalent; Brad Geesaman, Ghost Security; Rory McCune, Datadog 2023-04-21
  30. Least Privilege Containers: Keeping a Bad Day from Getting WorseGreg Castle & Vinayak Goyal, Google 2023-04-21
  31. Can You Keep a Secret? on Secret Management in KubernetesLiav Yona & Gal Cohen, Firefly 2023-04-21
  32. A Look Under the Hood of CNCF Security AuditsAdam Korczynski & David Korczynski, Ada Logics 2023-04-21
  33. 🦝 The Top 10 List of Istio Security Risks and Mitigation StrategiesJosé Carlos Chávez, Tetrate 2023-04-21
  34. 🦝 Secure the Build, Secure the Cloud: Using OIDC Tokens in CI/CD PipelinesAlex Ilgayev & Elad Pticha, Cycode 2023-04-21