Kicking Security Chain Attacks to the Curb with Kyverno and Notary in GitOps
Offered By: CNCF [Cloud Native Computing Foundation] via YouTube
Course Description
Overview
Explore a comprehensive conference talk on enhancing software supply chain security in GitOps using CNCF projects like Kyverno, Notary, and ORAS. Learn how to establish trust for container images and verify resources at scale in modern Kubernetes deployments. Discover the importance of distributing detached signatures and signed SBOMs for container images, and understand how the OCI v1.1 Spec's referrers API facilitates the association of supply chain artifacts with container images. Gain insights into implementing these tools to improve security checks pre-deployment and manage applications across multiple clusters and environments. Watch as Shuting Zhao and Feynman Zhou demonstrate practical techniques for verifying image integrity, security, and compliance in large-scale Kubernetes deployments.
Syllabus
Kicking Security Chain Attacks to the Curb with Kyverno and Notary... - Shuting Zhao & Feynman Zhou
Taught by
CNCF [Cloud Native Computing Foundation]
Related Courses
Kyverno - Deep Dive - Tech TalksMirantis via YouTube Kubernetes Native Policy Management with Kyverno
Ekoparty Security Conference via YouTube Hands-on Introduction to Sigstore - Securing the Software Supply Chain
Rawkode Academy via YouTube Hands-on with Policy Reporter - Kyverno Visibility Tool
Rawkode Academy via YouTube Introduction to Kyverno - Getting Started with Kubernetes Policy Management
Rawkode Academy via YouTube