Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Protecting Kubernetes Resource Manifests in End-to-End Software Development Lifecycle

OpenSSF via YouTube

Overview

Explore the importance of protecting Kubernetes resource manifests throughout the software development lifecycle in this conference talk by Yuji Watanabe from IBM. Learn about the Integrity Shield Project and its contribution to Sigstore for YAML manifest signing. Discover how this initiative addresses integrity issues in delivery and ensures end-to-end software supply chain integrity. Gain insights into the Kubernetes Policy Working Group's efforts and the implementation of secure manifest practices in Kyverno 1.8.0. Understand the significance of signing Kubernetes manifests and how it contributes to a more secure containerized environment.

Syllabus

Intro
Kubernetes resource manifests
Why sign Kubernetes manifests?
Integrity Shield Project
Present Idea to Sigstore Community
Contribution to Sigstore (YAML Manifest Signing)
YAML Manifest Signature
Kubernetes Policy Working Group call (Feb. 2022)
Securing Kubernetes manifests - Kyverno 1.8.0
SigstoreCon 2022 @ Detroit
End-to-end supply chain
Integrity issues in delivery
End-to-end software supply chain integrity

Taught by

OpenSSF

Reviews

Start your review of Protecting Kubernetes Resource Manifests in End-to-End Software Development Lifecycle

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.