Главная
Study mode:
on
1
Intro
2
Challenges of release
3
Supply chain security
4
Gain visibility into the supply chain
5
Machine readable manifest
6
Salsa overview
7
Bomb
8
Tecolote
9
Demo
10
Outro
Description:
Explore a comprehensive conference talk on open tools for secure supply chains in Kubernetes. Dive into the Kubernetes Release Engineering Team's efforts to achieve SLSA Level 3 compliance, resulting in a suite of open-source projects for supply chain security. Learn about building and publishing SBOMs, securely releasing staged images and artifacts, signing and verifying container images using Sigstore, and generating SLSA attestations. Discover how these tools can be applied beyond Kubernetes to other projects and companies. Witness a demo of a SLSA-compliant pipeline using Kubernetes Release Engineering tools, applicable to any project's release process. Gain insights into challenges of release, supply chain security, visibility enhancement, machine-readable manifests, and an overview of Salsa, Bomb, and Tecolote tools.

Open Tools for Secure Supply Chains in Kubernetes - From Release Engineering

Linux Foundation
Add to list