Kubernetes Podcast from Google

SRE for Everyone Else, with Steve McGhee

14 snips
Jun 18, 2021
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

MiniKube Security Scare

  • Dan Lorenc's work on MiniKube made him realize the security risks of users running binaries from unknown sources.
  • This led him to focus on supply chain security, including projects like TektonCD and Sigstore.
ADVICE

Securing Open Source

  • Improve security practices and make it easier for people to do the right thing.
  • Automate the capture of verifiable supply chain metadata and provide easy code signing.
ANECDOTE

Sigstore Key Ceremony

  • Sigstore's root certificate signing event involves five keyholders with individual hardware tokens. These tokens are used to sign everything and distributed to ensure resiliency, like Horcruxes.
Get the Snipd Podcast app to discover more snips from this episode
Get the app