Artwork

Content provided by Nicholas Chang. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Nicholas Chang or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Episode 31 - Container Security with Josh Duffney

33:37
 
Share
 

Manage episode 475480880 series 3551436
Content provided by Nicholas Chang. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Nicholas Chang or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

Send us a text

Josh walks us through the powerful combination of open-source CNCF projects that address different aspects of container supply chain security. Learn how Trivy scans for vulnerabilities, Copasetic performs targeted patching when base image updates aren't possible, Notation provides digital signatures to verify trust, and Ratify enforces security policies at deployment time. Together, these tools create a comprehensive approach to securing containers from build to runtime.
Ready to strengthen your container security posture? Listen now and discover how these tools can integrate into your existing workflows. Remember to follow us on social media to stay updated with more insights from community experts and share your thoughts on this episode!

  continue reading

Chapters

1. Introduction to Container Security (00:00:00)

2. Josh's Journey into Cloud Native (00:05:44)

3. Container Security Fundamentals (00:10:06)

4. Image Patching Strategies (00:16:02)

5. Continuous Patching Workflows (00:21:34)

6. Implementation Challenges and Future Trends (00:27:53)

7. Closing Thoughts and Book Recommendations (00:31:40)

33 episodes

Artwork
iconShare
 
Manage episode 475480880 series 3551436
Content provided by Nicholas Chang. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Nicholas Chang or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

Send us a text

Josh walks us through the powerful combination of open-source CNCF projects that address different aspects of container supply chain security. Learn how Trivy scans for vulnerabilities, Copasetic performs targeted patching when base image updates aren't possible, Notation provides digital signatures to verify trust, and Ratify enforces security policies at deployment time. Together, these tools create a comprehensive approach to securing containers from build to runtime.
Ready to strengthen your container security posture? Listen now and discover how these tools can integrate into your existing workflows. Remember to follow us on social media to stay updated with more insights from community experts and share your thoughts on this episode!

  continue reading

Chapters

1. Introduction to Container Security (00:00:00)

2. Josh's Journey into Cloud Native (00:05:44)

3. Container Security Fundamentals (00:10:06)

4. Image Patching Strategies (00:16:02)

5. Continuous Patching Workflows (00:21:34)

6. Implementation Challenges and Future Trends (00:27:53)

7. Closing Thoughts and Book Recommendations (00:31:40)

33 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide

Listen to this show while you explore
Play