Protect the Pipe - A Policy-based Approach for Securing CI/CD Pipelines
Offered By: CNCF [Cloud Native Computing Foundation] via YouTube
Course Description
Overview
Explore a cloud-native security framework for Tekton pipelines using in-toto, Kyverno, and sigstore in this conference talk. Learn about the unique security challenges faced by CI/CD pipelines and discover how to implement policy-based controls for pipeline composition, configurations, and execution. Gain insights into protecting critical assets in modern applications that are composed of numerous packages and delivered through automated CI/CD pipelines. Watch as the speakers demonstrate the use of open-source tools to attest and verify each pipeline resource and execution step using declarative policies, addressing the growing risks of attacks, vulnerabilities, and misconfigurations in rapid delivery environments.
Syllabus
Protect the Pipe! A Policy-based Approach for Securing CI/CD Pipe... Shripad Nadgowda & Jim Bugwadia
Taught by
CNCF [Cloud Native Computing Foundation]
Related Courses
Kyverno - Deep Dive - Tech TalksMirantis via YouTube Kubernetes Native Policy Management with Kyverno
Ekoparty Security Conference via YouTube Hands-on Introduction to Sigstore - Securing the Software Supply Chain
Rawkode Academy via YouTube Hands-on with Policy Reporter - Kyverno Visibility Tool
Rawkode Academy via YouTube Introduction to Kyverno - Getting Started with Kubernetes Policy Management
Rawkode Academy via YouTube