Protecting Kubernetes Resource Manifests in End-to-End Software Development Lifecycle
Offered By: OpenSSF via YouTube
Course Description
Overview
Explore the importance of protecting Kubernetes resource manifests throughout the software development lifecycle in this conference talk by Yuji Watanabe from IBM. Learn about the Integrity Shield Project and its contribution to Sigstore for YAML manifest signing. Discover how this initiative addresses integrity issues in delivery and ensures end-to-end software supply chain integrity. Gain insights into the Kubernetes Policy Working Group's efforts and the implementation of secure manifest practices in Kyverno 1.8.0. Understand the significance of signing Kubernetes manifests and how it contributes to a more secure containerized environment.
Syllabus
Intro
Kubernetes resource manifests
Why sign Kubernetes manifests?
Integrity Shield Project
Present Idea to Sigstore Community
Contribution to Sigstore (YAML Manifest Signing)
YAML Manifest Signature
Kubernetes Policy Working Group call (Feb. 2022)
Securing Kubernetes manifests - Kyverno 1.8.0
SigstoreCon 2022 @ Detroit
End-to-end supply chain
Integrity issues in delivery
End-to-end software supply chain integrity
Taught by
OpenSSF
Related Courses
Securing Your Software Supply Chain with SigstoreLinux Foundation via edX Hands-on Introduction to Sigstore - Securing the Software Supply Chain
Rawkode Academy via YouTube Protecting the World's Greatest Open Source Ecosystem with Sigstore
Devoxx via YouTube PGP vs Sigstore - The Match at Maven Central
Devoxx via YouTube Securing Your Infrastructure as Code Pipeline
Linux Foundation via YouTube