Learn Generative AI, Prompt Engineering, and LLMs for Free
The Most Addictive Python and SQL Courses
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
Explore how Tekton, an open-source Kubernetes-native CI/CD framework, implements supply chain security best practices to achieve SLSA Level 4 compliance in this 25-minute conference talk. Learn how Tekton Chains automatically captures TaskRun inputs, outputs, and metadata as signed in-toto attestations, generating SBOM and provenance data that satisfies SLSA Level 2 requirements for documented, tamper-resistant build provenance. Discover Tekton's progression to higher SLSA levels through integration with cluster identities using SPIFFE/SPIRE and Sigstore keyless signing, which attaches short-lived workload certificates to attestations for non-falsifiable provenance meeting SLSA Level 3 controls. Examine Tekton's Hermetic Execution Mode (Hermekton) that runs build steps in air-gapped containers to ensure fully reproducible builds for SLSA Level 4 hermeticity requirements. Understand how Tekton's Trusted Resources feature enables signing of Task and Pipeline definitions with runtime verification to prevent unauthorized modifications to build logic. Gain insights from concrete examples and lessons learned from developing these security features for software supply chain protection.
Syllabus
Path to SLSA 4: How Tekton Secures the Software Supply Chain - Vibhav Bobade & Vincent Demeester
Taught by
OpenSSF