Kubernetes Supply Chain Security - Building a Secure Software Factory
CNCF [Cloud Native Computing Foundation] via YouTube
AI Engineer - Learn how to integrate AI into software applications
AI, Data Science & Cloud Certificates from Google, IBM & Meta
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk presents a Kubernetes Software Factory approach to reducing software supply-chain risks. It covers lessons from the SUNBURST attacks and signing and verification methods using in-toto, TUF, SPIFFE, SPIRE, and sigstore.
Syllabus
Intro
About Control Plane
Agenda
Supply Chain Security
What is a Supply Chain
Software Supply Chain
Post Bare Metal
Software Factory
Supply Chain
Attack
Danger Zone
Supply chain compromises
How do we attack
Salsa
Reverse Shell
Trivia Scan
Signing
Container Images
Chain Guards
Reference Architecture
Entoto
Taught by
CNCF [Cloud Native Computing Foundation]