Stuck in Tutorial Hell? Learn Backend Dev the Right Way
Learn the Skills Netflix, Meta, and Capital One Actually Hire For
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
Explore how Tekton, an open-source Kubernetes-native CI/CD framework, implements supply chain security best practices to achieve SLSA Level 4 compliance in this 25-minute conference talk. Learn how Tekton Chains automatically captures TaskRun inputs, outputs, and metadata as signed in-toto attestations, generating SBOM and provenance data that satisfies SLSA Level 2 requirements for documented, tamper-resistant build provenance. Discover Tekton's progression to higher SLSA levels through integration with cluster identities using SPIFFE/SPIRE and Sigstore keyless signing, which attaches short-lived workload certificates to attestations for non-falsifiable provenance meeting SLSA Level 3 controls. Examine Tekton's Hermetic Execution Mode (Hermekton) that runs build steps in air-gapped containers to ensure fully reproducible builds for SLSA Level 4 hermeticity requirements. Understand how Tekton's Trusted Resources feature enables signing of Task and Pipeline definitions with runtime verification to prevent unauthorized modifications to build logic. Gain insights from concrete examples and lessons learned from developing these security features for software supply chain protection.
Syllabus
Path to SLSA 4: How Tekton Secures the Software Supply Chain - Vibhav Bobade & Vincent Demeester
Taught by
OpenSSF