Securing Cloud-Native Workloads: Hands-On with Notary Project, ORAS, and Ratify
About this video
What You'll Learn
- Sign container images and artifacts with Notation using trusted certificates.
- Store detached signatures in OCI registries alongside images with ORAS.
- Enforce admission-time trust checks in Kubernetes with Ratify and Gatekeeper.
Yi Zha from Microsoft demos how Notary Project, ORAS, and Ratify secure the container supply chain on Kubernetes: signing images with notation, storing signatures as OCI artifacts, and enforcing trust at admission via Ratify and OPA Gatekeeper.
Meet the Cast
Weekly Cloud Native insights
Stay ahead in cloud native
Tutorials, deep dives, and curated events. No fluff.
Comments