Главная
Study mode:
on
1
Intro
2
Agenda
3
Motivation? Sign Everything!
4
What is Fulcio
5
Hello (World) Signing
6
Hello (World) Commit Signing
7
Real-world scenario
8
Architecture - Pre Sigstore
9
Github Actions - Result
10
Gitlab Runner on K8s
11
Implementation
12
Insights
13
Takeaways
Description:
Explore the implementation of the Sigstore ecosystem in a corporate environment to enhance software artifact integrity and mitigate supply chain attacks. This conference talk delves into the challenges and solutions encountered while adopting Sigstore tooling across cloud-native, self-hosted, and on-premise environments. Learn about the trade-offs between self-hosting and using public instances of Rekor and Fulcio, implementing keyless commit signatures with gitsign, developing verification methodologies, utilizing SPIFFE/SPIRE for ephemeral build workload identities, and leveraging OIDC tokens for keyless signatures in various build environments. Gain valuable insights into the road to SLSA4 compliance and discover practical approaches to strengthen your organization's software supply chain security.

The Road to SLSA4 - Applying the Sigstore Ecosystem in a Corporate Environment

CNCF [Cloud Native Computing Foundation]
Add to list
0:00 / 0:00