Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

CNCF [Cloud Native Computing Foundation]

Securing CI/CD Systems Through eBPF

CNCF [Cloud Native Computing Foundation] via YouTube

Overview

Explore how eBPF technology can be leveraged to secure CI/CD pipelines in this technical talk from KubeCon + CloudNativeCon Europe 2023. Dive into the challenges of securing build environments across bare-metal, virtual machines, and ephemeral setups. Learn about innovative approaches to inject eBPF-based implants for inspecting, identifying, and protecting against malicious activity. Discover use cases including enhanced visibility over build processes, code and artifact integrity assurance, prevention of build process tampering, and implementation of tight network policies to safeguard sensitive information. Witness demonstrations of stopping critical software supply chain attacks while supporting major CI/CD platforms like GitHub Actions, Jenkins, GitlabCI, and CircleCI. Gain insights into eBPF tooling, architecture, functionality, and practical implementation through demos and real-world examples.

Syllabus

Introduction
Agenda
Alexs background
What is eBPF
eBPF tooling
Securing CICD
Why eBPF
SolarWinds
Installation of malicious dependencies
Tetragon
Architecture
Functionality
Installation
GitHub Action
Tracing
Deep Inspection
Integrity
Code Integrity
Network Protection
Network Protection Implementation
Demos
Whats next
Open Source
Conclusion
Questions

Taught by

CNCF [Cloud Native Computing Foundation]

Reviews

Start your review of Securing CI/CD Systems Through eBPF

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.