Imagine Secure by Design: Architecting Kubernetes with Trivy and DevSecOps
About this talk
This talk covers the essential strategies to secure Kubernetes clusters using Trivy, an open-source tool. The speakers demonstrate how to scan container images locally, in CI/CD pipelines, and within the cluster to identify vulnerabilities early on, as well as how to generate a Software Bill of Materials for enhanced transparency. They also showcase the implementation of the Trivy Operator for continuous scanning and explain how to present security scan results as metrics in Prometheus, visualized through Grafana, with an emphasis on CIS Benchmark compliance. The session blends perspectives from an architect and a DevSecOps engineer, highlighting the fusion of strategic planning and hands-on practices to enhance the security of Kubernetes pipelines and clusters.
More from this event
See all 108 talks →
Why are we still talking about containers? - Kelsey Hightower at ContainerDays 2025
46:56
Saxo Service Blueprint: Bridging Old and New World with Kubernetes Operators - Jinhong Brejnholt
36:25
Engineering Velocity, Building Trust: DevOps in 2025 - Stephan Stapel
33:17
Getting Started with eBPF Made Easy - Qasim Sarfraz & Michael Friese
33:05