Securing the Container Supply Chain with Notary, TUF, and Gatekeeper
Offered By: Linux Foundation via YouTube
Course Description
Overview
Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore container supply chain security in this 27-minute conference talk by Katie Novotny and Diego Casati from Microsoft. Delve into the importance of securing processes and controlling container workflows in light of recent software supply chain vulnerabilities. Learn about digital signatures as a method to ensure code integrity and compare various options for signing container images. Follow a demonstration using Notary, an open-source project based on The Update Framework (TUF), Gatekeeper, a customizable admission webhook for Kubernetes, and Ratify, a workflow engine for supply chain object verification. Discover how to implement these technologies in a typical CI/CD process and enforce policies in Kubernetes clusters. Gain insights into protecting your container deployments from potential malicious code intrusions.
Syllabus
Never Break the Chain: Securing the Container Supply Chain with... - Katie Novotny & Diego Casati
Taught by
Linux Foundation
Tags
Related Courses
Building the Software Supply Chain on Docker Official ImagesDocker via YouTube Demystify Modern Signing: Keys, Certificates, and Envelopes
CNCF [Cloud Native Computing Foundation] via YouTube Improving Package Repository Security - From White Papers to Practice
Linux Foundation via YouTube TUF Joins PyPI - Securing Package Delivery with The Update Framework
EuroPython Conference via YouTube Maintaining The Update Framework (TUF) - Insights and Contributions
CNCF [Cloud Native Computing Foundation] via YouTube