Cloud Native
Security Talks
RSS

KubeCon Europe 2025

Mind the Gap: Bridging Supply Chain Policy With Git-less GitOps and GUAC

Michael Lieberman, Kusari & Andrew Martin, ControlPlane

Abstract

In a live supply chain attack demo, we demonstrate the latest security features of Flux CD and OpenSSF GUAC together in a hardened, wide-scale production scenario. When the next XZ or log4shell vulnerability lands, see how to assess, respond, and prevent proliferation before or after an attacker gets a foothold in your systems. See how to defend against an assault on your dependency tree, prevent hostile insiders from escalating their privilege, and lock down your production environment to harden it against future threats. We: Use OCI-first Flux CD to remove network routes to Git servers from production GUAC to manage dependency inventory and bring signal to the noise of CVE updates Timoni to reliably patch, customise, and verify deployments before release Flux Autopilot to roll out multi-tenancy lockdown, horizontal and vertical scaling, and persistent storage across fleets of clusters

More from KubeCon Europe 2025

Open in the index →
  1. Trust No One: Secure Storage With Confidential ContainersAurélien Bombo, Microsoft 2025-04-02
  2. Signed, Sealed, Delivered - Sign and Verify All the ThingsJeremy Rickard, Microsoft 2025-04-02
  3. Securing AI Workloads: Building Zero-Trust Architecture for LLM ApplicationsRohit Ghumare, Taikun & Joinal Ahmed, NTG 2025-04-02
  4. Weaving a VEX Feed Through the Kubernetes ProjectAdolfo García Veytia, Stacklok 2025-04-03
  5. Redefining Access Control: Scaling Policy as Code for Humans and AI AgentsRaz Cohen, Permit.io 2025-04-03
  6. Open Source Malware or a Vulnerability? The Philosophical Debate and How To MitigateBrian Fox, Sonatype; Madelein van der Hout, Forrester Research Inc.; Santiago Torres-Arias, Purdue University 2025-04-03
  7. Identity-based Trust - Till Death Do We Part?John Kjell, ControlPlane & Kairo De Araujo, Independent 2025-04-03
  8. IAM, Agent: Identity for Autonomous AIMatthew Bates, Cofide 2025-04-03
  9. ​​SPIFFE in Practice: Universal Identity for WebAssembly WorkloadsJoonas Bergius, Cosmonic & Colin Murphy, Adobe 2025-04-03
  10. Zero Trust at Shopify Scale: Automating MTLS Across Thousands of ServicesDani Santos & Michelle Mali, Shopify 2025-04-04
  11. Why Don’t We Have Both? Track Build- and Run-time Information for Security With Kubescape and GUACJeff Mendoza, Kusari & Ben Hirschberg, ARMO 2025-04-04
  12. From Chaos To Control: Migrating Access Control To OpenFGA in a Multi-Tenant WorldJo Guerreiro, Grafana Labs & Poovamraj Thanganadar Thiagarajan, Okta 2025-04-04
  13. Fresh Secrets From the Docks: Lessons Learnt From Analyzing 180,000 Public DockerHub ImagesGuillaume Valadon, GitGuardian 2025-04-04
  14. Enhancing Software Composition Analysis Resilience Against Container Image ObfuscationAgathe Blaise, Thales & Jacopo Bufalino, CNAM 2025-04-04
  15. EVAPorating Kubernetes Security Risk: Adopting Validating Admission Policy at ScaleKaitlyn Lee & Jordan Conard, Datadog 2025-04-04
  16. Do Your Containers Even Lift – A Hardening Guide for K8s ContainersCailyn Edwards & Daniel Murphy, Okta 2025-04-04
  17. Container Runtimes... on Lockdown: The Hidden Costs of Multi-tenant WorkloadsLewis Denham-Parry, Edera & Caleb Woodbine, ii.nz 2025-04-04
  18. Compliance at the Speed of Innovation: Leveraging AI-Driven Automation for Real-Time Regulatory ReadLarry Carvalho, RobustCloud LLC; Simon Metson, EnterpriseDB; Robert Ficcaglia, Sunstone Secure, LLC; Anca Sailer, Red Hat / IBM; Yuji Watanabe, IBM Japa 2025-04-04