KubeCon China 2018 | The State of your Supply Chain, with Andy Martin
Container security often focuses on runtime best-practices whilst neglecting the software shipped in the supply chain. In this talk we detail an ideal software supply chain, describe the current state of the ecosystem, and dig into specific tools. Grafeas, Kritis, in-toto, Clair, Micro Scanner, TUF, and Notary are covered, and we demo how to identify a vulnerable image then automatically rebuild and redeploy it.
Nov 2018ShanghaiContainer securitySupply chain security