Overview
Explore how eBPF technology can be leveraged to secure CI/CD pipelines in this technical talk from KubeCon + CloudNativeCon Europe 2023. Dive into the challenges of securing build environments across bare-metal, virtual machines, and ephemeral setups. Learn about innovative approaches to inject eBPF-based implants for inspecting, identifying, and protecting against malicious activity. Discover use cases including enhanced visibility over build processes, code and artifact integrity assurance, prevention of build process tampering, and implementation of tight network policies to safeguard sensitive information. Witness demonstrations of stopping critical software supply chain attacks while supporting major CI/CD platforms like GitHub Actions, Jenkins, GitlabCI, and CircleCI. Gain insights into eBPF tooling, architecture, functionality, and practical implementation through demos and real-world examples.
Syllabus
Introduction
Agenda
Alexs background
What is eBPF
eBPF tooling
Securing CICD
Why eBPF
SolarWinds
Installation of malicious dependencies
Tetragon
Architecture
Functionality
Installation
GitHub Action
Tracing
Deep Inspection
Integrity
Code Integrity
Network Protection
Network Protection Implementation
Demos
Whats next
Open Source
Conclusion
Questions
Taught by
CNCF [Cloud Native Computing Foundation]