Cloud Native
Security Talks
RSS

KubeCon Europe 2025

Signed, Sealed, Delivered - Sign and Verify All the Things

Jeremy Rickard, Microsoft

Abstract

You’re a cluster operator facing evolving supply chain threats. You’re getting hit with rate-limits causing service availability issues. A configuration change made it into production and deployed unapproved images. Someone got access to your registry and tampered with an image. How do we handle these threat vectors? Digital signing and policy enforcement can help! In this talk, we’ll look at how CNCF projects like ORAS, Notary, Flux, and Kyverno can be used together to ensure that everything in your production clusters, from images to configuration YAML, comes from a trusted source and has been digitally signed to ensure it hasn’t been tampered with and. how to do this with a registry you control. You’ll leave this session with knowledge of how these tools work together to enable you to protect your clusters, some of the gaps, and how you can address them. Jeremy will walk through a complete end-to-end experience and provide a Github repo with samples to take home.

More from KubeCon Europe 2025

Open in the index →
  1. Trust No One: Secure Storage With Confidential ContainersAurélien Bombo, Microsoft 2025-04-02
  2. Securing AI Workloads: Building Zero-Trust Architecture for LLM ApplicationsRohit Ghumare, Taikun & Joinal Ahmed, NTG 2025-04-02
  3. Weaving a VEX Feed Through the Kubernetes ProjectAdolfo García Veytia, Stacklok 2025-04-03
  4. Redefining Access Control: Scaling Policy as Code for Humans and AI AgentsRaz Cohen, Permit.io 2025-04-03
  5. Open Source Malware or a Vulnerability? The Philosophical Debate and How To MitigateBrian Fox, Sonatype; Madelein van der Hout, Forrester Research Inc.; Santiago Torres-Arias, Purdue University 2025-04-03
  6. Mind the Gap: Bridging Supply Chain Policy With Git-less GitOps and GUACMichael Lieberman, Kusari & Andrew Martin, ControlPlane 2025-04-03
  7. Identity-based Trust - Till Death Do We Part?John Kjell, ControlPlane & Kairo De Araujo, Independent 2025-04-03
  8. IAM, Agent: Identity for Autonomous AIMatthew Bates, Cofide 2025-04-03
  9. ​​SPIFFE in Practice: Universal Identity for WebAssembly WorkloadsJoonas Bergius, Cosmonic & Colin Murphy, Adobe 2025-04-03
  10. Zero Trust at Shopify Scale: Automating MTLS Across Thousands of ServicesDani Santos & Michelle Mali, Shopify 2025-04-04
  11. Why Don’t We Have Both? Track Build- and Run-time Information for Security With Kubescape and GUACJeff Mendoza, Kusari & Ben Hirschberg, ARMO 2025-04-04
  12. From Chaos To Control: Migrating Access Control To OpenFGA in a Multi-Tenant WorldJo Guerreiro, Grafana Labs & Poovamraj Thanganadar Thiagarajan, Okta 2025-04-04
  13. Fresh Secrets From the Docks: Lessons Learnt From Analyzing 180,000 Public DockerHub ImagesGuillaume Valadon, GitGuardian 2025-04-04
  14. Enhancing Software Composition Analysis Resilience Against Container Image ObfuscationAgathe Blaise, Thales & Jacopo Bufalino, CNAM 2025-04-04
  15. EVAPorating Kubernetes Security Risk: Adopting Validating Admission Policy at ScaleKaitlyn Lee & Jordan Conard, Datadog 2025-04-04
  16. Do Your Containers Even Lift – A Hardening Guide for K8s ContainersCailyn Edwards & Daniel Murphy, Okta 2025-04-04
  17. Container Runtimes... on Lockdown: The Hidden Costs of Multi-tenant WorkloadsLewis Denham-Parry, Edera & Caleb Woodbine, ii.nz 2025-04-04
  18. Compliance at the Speed of Innovation: Leveraging AI-Driven Automation for Real-Time Regulatory ReadLarry Carvalho, RobustCloud LLC; Simon Metson, EnterpriseDB; Robert Ficcaglia, Sunstone Secure, LLC; Anca Sailer, Red Hat / IBM; Yuji Watanabe, IBM Japa 2025-04-04