Session
Hardening Kubernetes: Our Journey to FIPS Compliance
Security and regulatory compliance are becoming baseline requirements for running Kubernetes in sensitive environments. FIPS 140-3 defines strict cryptographic standards, shaping which libraries can be used and how binaries are built and tested. But what does it actually mean for a Kubernetes distribution to be “FIPS compliant”?
We break down what FIPS compliance entails in practice: validated crypto modules, consistent toolchain builds, and verification that all components use only approved cryptographic primitives. We’ll share our journey of bringing Canonical Kubernetes into compliance, including challenges, end-to-end validation, and CI integration.
Attendees will walk away with a deep understanding of what compliance actually requires, why it matters, and how it affects the architecture and engineering decisions of a cloud-native project. We'll clarify the difference between being “compliant in principle” versus “in practice,” and highlight the importance of rigorous validation.
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top