Explore a comprehensive conference talk on securing CI/CD pipelines and establishing a chain of custody in Kubernetes environments. Dive into the critical aspects of ensuring end-to-end security in software delivery processes, including transmission security, developer key rotation, signed git commits, and independently reproducible build verification. Learn about implementing signed release artifacts and runtime authority for immutable containers to achieve a secure chain of custody from development to production. Gain valuable insights into protecting your entire software delivery process against potential compromises, even with Kubernetes' secure-by-default posture.
Securing the Perimeter - CFCR/CFAR Chain of Custody With CI/CD Pipelines
CNCF [Cloud Native Computing Foundation] via YouTube
Overview
Syllabus
Securing the Perimeter - CFCR/CFAR Chain of Custody With CI/CD Pipelines - Keith Strini, Pivo
Taught by
CNCF [Cloud Native Computing Foundation]