youtube image
From YouTube: Strengthening Supply Chain Security By Enforcing Policies Using OPA G... Rita Zhang & Sertaç Özercan


Don’t miss out! Join us at our next event: KubeCon + CloudNativeCon Europe 2022 in Valencia, Spain from May 17-20. Learn more at The conference features presentations from developers and end users of Kubernetes, Prometheus, Envoy, and all of the other CNCF-hosted projects.

Strengthening Supply Chain Security By Enforcing Policies Using OPA Gatekeeper on Kubernetes- Rita Zhang & Sertaç Özercan, Microsoft

Open Policy Agent (OPA) Gatekeeper is a general-purpose policy engine for Kubernetes and provides various means to validate and mutate Kubernetes resources to enforce policies. In many of these scenarios, this data has to be either built-in, static or user-defined. However, to strengthen supply chain security this data needs to be dynamic, and is usually stored in external services, such as container registries. With Gatekeeper external data feature, Gatekeeper offers a provider-based model to enforce policies to strengthen supply chain security by validating artifacts like checking for image vulnerabilities, image signatures, software bill of materials (SBOM). In this talk, we are going to talk about how OPA Gatekeeper can be used to enforce policies to validate container images and secure your Kubernetes cluster.