PLAY PODCASTS
The new old: Supply Chain Security (froscon2023)

The new old: Supply Chain Security (froscon2023)

(with Kubernetes this time)

Chaos Computer Club - archive feed · delet0r

August 6, 202333m 59s

Audio is streamed directly from the publisher (cdn.media.ccc.de) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.

Show Notes

We are the SiC (Signed Container) project and in this talk we give an overview about the problems Kubernetes and its tooling poses in the context of supply chain security, followed by a general introduction to the Sigstore tools, that are an answer to some of those problems, specifically artifact signing and validation. Finally, we will present our project results, in which we implemented an end-to-end container signing and verification process for IRIS-Connect with said tools with the aim to define a distribution like, batteries included setup to ease the migration to a world in which containers are signed and validated automatically in a distributed fashion. about this event: https://programm.froscon.org/2023/events/2901.html

Topics

froscon202329012023Security