YoVDO

Protecting Kubernetes Resource Manifests in End-to-End Software Development Lifecycle

Offered By: OpenSSF via YouTube

Tags

Kubernetes Courses Software Supply Chain Security Courses Sigstore Courses Kyverno Courses OpenSSF Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the importance of protecting Kubernetes resource manifests throughout the software development lifecycle in this conference talk by Yuji Watanabe from IBM. Learn about the Integrity Shield Project and its contribution to Sigstore for YAML manifest signing. Discover how this initiative addresses integrity issues in delivery and ensures end-to-end software supply chain integrity. Gain insights into the Kubernetes Policy Working Group's efforts and the implementation of secure manifest practices in Kyverno 1.8.0. Understand the significance of signing Kubernetes manifests and how it contributes to a more secure containerized environment.

Syllabus

Intro
Kubernetes resource manifests
Why sign Kubernetes manifests?
Integrity Shield Project
Present Idea to Sigstore Community
Contribution to Sigstore (YAML Manifest Signing)
YAML Manifest Signature
Kubernetes Policy Working Group call (Feb. 2022)
Securing Kubernetes manifests - Kyverno 1.8.0
SigstoreCon 2022 @ Detroit
End-to-end supply chain
Integrity issues in delivery
End-to-end software supply chain integrity


Taught by

OpenSSF

Related Courses

Security Is an Ecosystem - We Can't Be Secure in Isolation
Linux Foundation via YouTube
Improving the Security of a Large Open Source Project One Step at a Time
Linux Foundation via YouTube
Simplifying Coordinating Vulnerabilities and Disclosures in Open Source Projects
Linux Foundation via YouTube
SLSA in Action: Securing the Software Supply Chain
Linux Foundation via YouTube
Implementing OpenSSF Best Practices Badges and Scorecards for Project Security
Linux Foundation via YouTube