Kubernetes Third Party Aud... Iain Smart, Amir Montazery, Rey Lejano, Tabitha Sable & Pietro Tirenna
About this talk
This talk covers the recent third-party audit of Kubernetes, organized by SIG-Security-Audit in collaboration with the Open Source Technology Improvement Fund and conducted by Shielder. The speakers, including experts from AmberWolf, Red Hat, and Datadog, discuss the audit process, providing insights into planning, logistics, and experiences of open-source collaboration with vendors. They highlight the evolution of the audit approach, examining non-core components such as Cluster API, Konnectivity, and Image Builder, and present key findings, including supply chain risks, insecure design patterns, and unsafe defaults. This session offers valuable lessons for developers and security practitioners involved in the cloud-native community.
More from this event
See all 436 talks →
Best of KubeCon + CloudNativeCon Amsterdam 2026
2:17
The Quiet Work of Forever: Sustaining Open Source Communities - O. Hope Amaechi-Okorie, JSON Schema
26:24
Evolving KServe: The Unified Model Inference Platform for Both Predictive and... F. Spolti & J. Lee
32:40
Preventing S3 Cost Storms: Applying Cortex’s Efficiency Lessons to I/O-Heav... A. Fishman-Lichterman
5:32