Argo CD end user threat model
A comprehensive threat model analysis of a production setup of @argoproj:
* Representations of threat landscapes through attack trees
* Security best practices
* Deployment architecture
+ more!
By @controlplaneiohttps://cncf.io/blog/2023/04/21/argo-cd-end-user-threat-model-security-considerations-for-hardening-declarative-gitops-cd-on-kubernetes/…
📣Call for speakers 📣
We're looking for interesting DevSecOps talks, regardless of whether you're a novice or professional speaker for DevSecCon24 2023! Submit your session TODAY! 👉🏽https://sessionize.com/devseccon24-2023/…
KubeCon was busy, so re-posting a couple things:
1) Chainguard assessed Argo CD to be SLSA Level 3 (darn-good supply chain security). https://cncf.io/blog/2023/04/19/building-secure-software-supply-chains-in-cncf-with-slsa-assessments/…
2) ControlPlane published an end user threat model (hardening guide) for Argo CD. https://cncf.io/blog/2023/04/21/argo-cd-end-user-threat-model-security-considerations-for-hardening-declarative-gitops-cd-on-kubernetes/…
, as he explores the complex world of Cloud Native supply chains, focusing on malicious internal threat actors and software implants.📢
Get your #WTFisSRE conference tickets today🎟️
.
I like that it begins with a list of references to important projects in the space. I'm also a sucker for anyone that references "Reflections on trusting trust."
https://youtu.be/7CMhIDAPjEs
Studious CTF preparation from the assembled cloud native security venturers at KubeCon's Security Village! Intro today, full day of Kubernetes cluster hacking tomorrow 💥☸️🌩️ with
The clock is ticking and it's less than 72 hours until the first-ever #SecurityVillage#Experience at #KubeCon. 🎉🎉
Are you as excited as us!!? Let us know in the comments.
Read more about Security Village at
Set sail with Captain Alex Williams as he uncovers buried treasure with ControlPlane CEO Andrew Martin in this demo. https://bit.ly/43xol55#Kubernetes#CloudNative#CloudSecurity@controlplaneio
KubeCon is looking busy ! As well as my two sessions in the main schedule, I’ll also be appearing on a panel on Wednesday night for the Amsterdam Cloud Security Meetup along with
A KubeCon offer from @controlplaneio: Lightspeed Security in our Threat Roomhttps://lnkd.in/ekP-JtbZ — threat model projects, systems, supply chains, glints of the eye, we appraise and review it all in 25m sessions with our trademark high-impact threat modelling process …Show more
: Lightspeed Security in our Threat Room⚡https://lnkd.in/ekP-JtbZ — threat model projects, systems, supply chains, glints of the eye, we appraise and review it all in 25m sessions with our trademark high-impact threat modelling process ☸️🌩️…Show more
: Lightspeed Security in our Threat Room⚡https://lnkd.in/ekP-JtbZ — threat model projects, systems, supply chains, glints of the eye, we appraise and review it all in 25m sessions with our trademark high-impact threat modelling process ☸️🌩️…Show more
Hi #Kubernetes minded friends! As preparation for #KubeConEu, we're running a Live on the future of containers & kubernetes security. If you pop a question in the comments before Thurs. 10am PST, we'll do our best to cover it!
Details: https://lnkd.in/gvxdyxn2
We did a survey of the security landscape of package managers! Find out how your favorite package managers (PyPI, RubyGems, Golang, Maven, etc.) view the different aspects of supply chain security!
Taking the Pulse of Leading Software Repositories’ Security https://hubs.la/Q01KckNj0 The OpenSSF Securing Software Repository Working Group surveyed the maintainers of 11 leading software repositories to learn about their current security posture & future plans
CEO Andrew Martin is great. The idea of the game is for people to explore find where “the bodies are buried” and follow the processes to find the flags in order to secure #Kubernetes clusters.