Loading…
In-person + Virtual
18-21 April
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon Europe 2023 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Central European Summer Time (UTC +2). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date." The schedule is subject to change and session seating is available on a first-come, first-served basis. 
Thursday, April 20 • 15:25 - 16:00
Checking the Chains at the Gate: Building Supply Chain Policies with Gatekeeper and Ratify - Jeremy Rickard, Microsoft

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.


If you're running Kubernetes in production, you've probably thought about how to keep your clusters and their workloads in compliance with corporate or regulatory policies. In Kubernetes, you'll probably do this with an admission controller. An admission controller intercepts requests to the Kubernetes API server and allows you to validate or change it. Gatekeeper is an Open Polciy Agent based admission controller that enables enforcement of CRD-based policies. These policies normally act on data within the request or other static data within your cluster. However, sometimes that's not enough. As Software Supply Chain security becomes more important, our policies need to consider more external artifacts. Maybe you want to verify that images are signed or that the SBOM for a service doesn't have that latest OpenSSL CVE. Gatekeeper's external data feature allows you to do just this, through the use of plugin providers. Ratify is an open source project that enables verification of supply chain artifacts and can act provider for Gatekeeper. In this talk, Jeremy will show how to you can use Gatekeeper, Ratify, and OCI registries to develop supply chain security focused policies for your clusters, as well as how to write your own custom verifiers to meet evolving policy requirements.

Speakers
avatar for Jeremy Rickard

Jeremy Rickard

Principal Software Engineer, Microsoft Azure
Jeremy Rickard is a principal software engineer at Microsoft, where he works on supply chain security projects in the Azure Container Upstream team. He is also a chair for SIG Release, a co-chair for the Long Term Support (LTS) working group, and was the release lead for Kubernetes... Read More →



Thursday April 20, 2023 15:25 - 16:00 CEST
Auditorium + Balcony | Ground + First Floor | Congress Centre
  Security + Identity
  • Content Experience Level Any
  • Talk Type In-Person
  • Presentation Slides Attached Yes