Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Linux Foundation

Software Supply Chain Aspects in Infrastructure as Code

Linux Foundation via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This session examines software supply chain risks created by reusing infrastructure-as-code snippets, templates, and container images. It discusses IaC scanning and security measures including verifiable metadata, signatures, and reproducible builds.

Syllabus

Intro
Infrastructure as Code
Software Supply Chain
Software Security
(some) laC Efficiency
Find a HELM chart
Levels of Typosquatting
Supply Chain Security & laC
Container Supply Chain
debian:buster-slim
You're wrong, because...
The importance of metadata
Verifiable metadata
Distroless containers
Reproducible Builds
Reproducibility
Signatures (e.g. cosign)
These would also be signed..
What is the solution?
Securing Container Creation
Already adopted by GitLab
key takeaways

Taught by

Linux Foundation

Reviews

Start your review of Software Supply Chain Aspects in Infrastructure as Code

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.