Supply Chain Reaction - A Cautionary Tale in Kubernetes Security
CNCF [Cloud Native Computing Foundation] via YouTube
Overview
Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Explore a keynote presentation that reveals how supply chain vulnerabilities can compromise even the most secure Kubernetes environments and learn practical defense strategies using OpenSSF tools. Follow a real-world attack scenario where traditional security measures like network policies, mTLS, and GitOps workflows prove insufficient against sophisticated supply chain exploits including poisoned commits, tainted build tools, malicious container images, and backdoored dependencies. Discover how attackers can bypass seemingly bulletproof Kubernetes clusters and understand the challenges faced by DevOps engineers in maintaining security. Learn practical countermeasures using OpenSSF projects including Sigstore for image signing, SLSA attestations for build security, OpenVEX and SBOM for dependency protection, and gittuf for source control integrity. Gain insights into transforming supply chain hardening into effective defense-in-depth strategies without overwhelming developers, and understand how to implement and enforce OpenSSF tooling coordinated through the OSPS Baseline while making practical improvements to CI/CD and GitOps integrity workflows.
Syllabus
Keynote: Supply Chain Reaction: A Cautionary Tale in K8s Security - S. Potter & A.G. Veytia (ASL)
Taught by
CNCF [Cloud Native Computing Foundation]