Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Linux Foundation

A Step Closer to Secure Development: Using in-Toto and OPA Gatekeeper to Verify Artifact Integrity

Linux Foundation via YouTube

Overview

Explore secure software development practices in this 45-minute conference talk from the Linux Foundation. Learn how to verify artifact integrity throughout the software supply chain using in-toto and OPA Gatekeeper. Discover the benefits of automating development processes from 'git commit' to 'kubectl apply' while addressing security concerns. Examine the risks associated with various automation implementations and understand the importance of maintaining consistency and security. Gain insights into in-toto's pioneering frameworks and tools, including subprojects Witness and Archivista, designed to secure software development, building, testing, and packaging. Follow an end-to-end demonstration of securely developing container images for Kubernetes using these tools in conjunction with Open Policy Agent's admission controller, Gatekeeper.

Syllabus

A Step Closer to in-Toto’lly Secure: Using in-Toto and OPA Gatekeeper...- Tom Meadows & John Kjell

Taught by

Linux Foundation

Reviews

Start your review of A Step Closer to Secure Development: Using in-Toto and OPA Gatekeeper to Verify Artifact Integrity

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.