Automatically TUF about Container Image Security in Kubernetes - Zach Arnold
About this talk
This talk introduces The Update Framework (TUF) and its companion project Notary, essential tools in the cloud native ecosystem that provide robust assurances regarding the integrity of software packages, particularly container images, within environments like Kubernetes. The session begins by clarifying the concepts behind TUF and Notary, followed by a demonstration on establishing image signing within a build pipeline. The discussion culminates in the implementation of restrictions on deployable container images in Kubernetes to those that are signed, utilizing Validating and Mutating Admission Webhook Controllers. Attendees will gain practical skills to apply similar processes in their own CI/CD workflows.