Session

Pragmatically Securing GitOps Deployment Pipelines

Sigstore offers a robust solution for the secure signing of diverse artifacts, including OCI images and blob files, ensuring their authenticity and integrity in the software supply chain.

Within the project toolkit, I will introduce innovative concepts aimed at implementing security policies for package deployments in Kubernetes clusters. The goal is to showcase the practical process of constructing secure CI/CD pipelines, encompassing pivotal elements like attestations, automated signatures, and artifact validation, all rooted in GitOps principles.

This approach to preserving the integrity of software artifacts empowers Site Reliability Engineers (SREs) and system administrators to significantly reduce vulnerabilities stemming from compromised Infrastructure as Code (IaC) repositories, thereby mitigating the potential for software supply chain attacks.

Amim Knabben

Staff R&D Software Engineer - Broadcom

Florianópolis, Brazil

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top