Fast & Secure: Package, Sign, Verify, and Deploy - Koray Oksay and Batuhan Apaydin
About this talk
This session explores the crucial intersection of supply chain security and platform engineering, focusing on technologies like GitOps, Sigstore, and OCI artifacts and registries. The speaker demonstrates how to store Helm releases in an OCI registry, secure them with Cosign, and verify the signature using Flux, offering practical insights through a well-structured demo. Participants will gain an understanding of how Helm, since version 3.8.0, supports OCI registries, and learn about Flux's capability to verify packages signed with Cosign, all illustrated with the Zot registry. The speaker, Koray Oksay, is a Kubernetes Consultant and Trainer at Kubermatic, bringing over 20 years of experience in various technical roles across industries such as advertising, banking, and telecommunications.
More from this event
See all 77 talks →
Fireside Chat with Kelsey Hightower & Sebastian Scheele
44:16
Coping with Zero Days with Cilium Tetragon - Liz Rice
42:15
Building Trust in Fintech: DevSecOps Strategies at Saxo Bank - Jinhong Brejnholt
35:35
Seven years and counting – The DevOps journey at Hermes Germany - Stephan Stapel
34:16