Hands-on Introduction to sigstore
In this episode, Dan guides us through everything we need to get started with Project sigstore.
๐ฟ Rawkode Live
Hosted by David McKay / ๐ฆ https://twitter.com/rawkode
Website: https://rawkode.live
Discord Chat: https://rawkode.live/chat
#RawkodeLive
๐ฐ Timeline
00:00 - Holding screen
01:15 - Introductions
03:00 - What is Project sigstore?
11:30 - Signing & Verifying Container Images with cosign
34:00 - cosign: keyless mode
41:00 - Transparency Logs with rekor
55:00 - Using Kyverno for Signed Image Policies
๐ฅ About the Guests
Dan Lorenc
OSS Supply Chain Security at Google!
๐ฆ https://twitter.com/lorenc_dan
๐งฉ https://github.com/dlorenc
๐ https://www.danlorenc.com/
๐จ About the Technologies
sigstore
sigstore is a Linux Foundation project.
sigstore is a project with the goal of providing a public good / non-profit service to improve the open source software supply chain by easing the adoption of cryptographic software signing, backed by transparency log technologies.
sigstore will seek to empower software developers to securely sign software artifacts such as release files, container images, binaries, bill of material manifests and more. Signing materials are then stored into a tamper resistant public log
sigstore will be free to use for all developers and software providers, with sigstoreโs code and operation tooling being 100% open source and maintained / developed by the sigstore community.
๐ https://sigstore.dev
๐ฆ https://twitter.com/projectsigstore
๐งฉ https://github.com/sigstore
##SupplyChain
Technologies used in this video
Related Videos

Hands-On with Preq - Community-Driven Reliability Problem Detection
Join us for an exclusive live stream as we explore Preq (pronounced "preek"), the free and open-source tool that's revolutionizing how teams detect and prevent reliability issues before customers noti

Hands-On with Kairos - Edge Kubernetes Made Simple
Join us for an exclusive live stream as we dive deep into Kairos, the open-source project that's revolutionizing OS lifecycle management across edge, cloud, and bare metal environments!

Hands-on Introduction to k0rdent
**Hands-on Introduction to k0rdent**

Comments