You are on page 1of 16

Trust In Honk,

Tie Up Your YAML


A kpack experience
Ram Iyengar
Chief Evangelist at Cloud Foundry Foundation

S/w Supply Chain Security Enthusiast

Recovering from log4jshell trauma


Security as an afterthought

But, that’s changing!


More trust along build pipelines
Result of experiments
Experiment #1

SBOMs

In the wild!
Experiment #2

SLSA

For real!
Experiment #3

cosign

Low effort, high reward!


Who is
building it?

Where is
What’s
it being
being built?
built?
cosign

SLSA SBOMs
app

Node js lang
</>
Node libs
...
Node JS
OS
app

npm app image


yarn
Requirements Standardized and
Hermetic and
Version control auditable source
Guarantees reproducible build,
Hosted Build and build,
Levels 2-person review
provenance

0 ❌

1 ✅

2 ✅ ✅

3 ✅ ✅ ✅

4 ✅ ✅ ✅ ✅
OIDC Connect

JSON Web Token

Certificate Signing
Request

x.509

Rekor Entry

Signed Entry Timestamp

Data, signature,
certificate, timestamp

Download and verification


demo!
@ramiyengar

You might also like