Главная
Study mode:
on
1
Introduction
2
Agenda
3
Alexs background
4
What is eBPF
5
eBPF tooling
6
Securing CICD
7
Why eBPF
8
SolarWinds
9
Installation of malicious dependencies
10
Tetragon
11
Architecture
12
Functionality
13
Installation
14
GitHub Action
15
Tracing
16
Deep Inspection
17
Integrity
18
Code Integrity
19
Network Protection
20
Network Protection Implementation
21
Demos
22
Whats next
23
Open Source
24
Conclusion
25
Questions
Description:
Explore how eBPF technology can be leveraged to secure CI/CD pipelines in this technical talk from KubeCon + CloudNativeCon Europe 2023. Dive into the challenges of securing build environments across bare-metal, virtual machines, and ephemeral setups. Learn about innovative approaches to inject eBPF-based implants for inspecting, identifying, and protecting against malicious activity. Discover use cases including enhanced visibility over build processes, code and artifact integrity assurance, prevention of build process tampering, and implementation of tight network policies to safeguard sensitive information. Witness demonstrations of stopping critical software supply chain attacks while supporting major CI/CD platforms like GitHub Actions, Jenkins, GitlabCI, and CircleCI. Gain insights into eBPF tooling, architecture, functionality, and practical implementation through demos and real-world examples.

Securing CI/CD Systems Through eBPF

CNCF [Cloud Native Computing Foundation]
Add to list