About this talk
This talk addresses the rising complexities associated with micro-service architecture and distributed systems, particularly in the context of software supply chain attacks on modern applications. The speaker introduces the essential concepts of container image signing and attestation, emphasizing the importance of ensuring that all images originate from trusted sources and remain untampered. Key aspects include the technical details and advantages of keyless signing, alongside methods for automating the verification of image signatures within Kubernetes workloads. The session also explores practical techniques and tools that facilitate the integration of image verification into the software delivery lifecycle. Jan Bruder, a solution architect at SUSE, draws on his extensive experience with cloud-native technologies and Kubernetes to provide insights on securing container-based deployment processes.
More from this event
See all 77 talks →
Fireside Chat with Kelsey Hightower & Sebastian Scheele
44:16
Coping with Zero Days with Cilium Tetragon - Liz Rice
42:15
Building Trust in Fintech: DevSecOps Strategies at Saxo Bank - Jinhong Brejnholt
35:35
Seven years and counting – The DevOps journey at Hermes Germany - Stephan Stapel
34:16