Search results for: security audit


The Register: "Captain, we've detected a disturbance in space-time. It's coming from Earth. Someone audited the Kubernetes source"

Posted on August 6, 2019

The CNCF engaged two security firms, Trail of Bits and Atredis Partners, to poke around Kubernetes code over the course of four months. The companies looked at Kubernetes components involved in networking, cryptography, authentication, authorization, secrets…


TOC approves CNCF SIGs and creates security and storage SIGs

Posted on June 24, 2019

Earlier this year, the Technical Oversight Committee (TOC) voted to create CNCF Special Interest Groups (SIGs). CNCF SIGs are currently being bootstrapped in various focus areas and primarily led by recognized experts and supported by contributors. They…


Kubernetes in highly restrictive environments: meeting the needs of enterprise governance & security

Posted on June 4, 2019

Installing Kubernetes is easy. Ensuring it complies with your organization’s enterprise governance and security requirements isn’t. Oleg will outline a plan to use the technology while meeting enterprise security requirements. In this technically-focused talk, he’ll summarize…


9 Kubernetes security best practices everyone must follow

Posted on January 14, 2019

By Connor Gilbert, product manager at StackRox Last month, the Kubernetes ecosystem was shaken by the discovery of the first major security flaw in Kubernetes, the world’s most popular container orchestrator. The vulnerability – CVE-2018-1002105 –…


CNCF to host two security projects – Notary and TUF specification

Posted on October 24, 2017

Riyaz Faizullabhoy, Docker Security Engineer, today announced on stage at Open Source Summit Europe, that the Cloud Native Computing Foundation (CNCF) Technical Oversight Committee (TOC) has voted Notary in as our 13th hosted project and TUF…


OpenTelemetry has graduated… Now what?

Posted on July 24, 2026 | Adriana Villela (Dynatrace LLC) and Reese Lee (New Relic)

In case you missed it: OpenTelemetry (OTel) has officially achieved CNCF graduated status! It now stands proudly alongside amazing open source projects such as Kubernetes and Prometheus, to name just a few. It’s been a long journey, and we’re very…


Securing CI/CD for an open source project, part 3: Credentials, verification, and what’s next

Posted on June 26, 2026 | André Martins (Cilium maintainer and Software Engineer, Isovalent at Cisco) and Feroz Salam (Cilium Security Team and Security Engineer, Isovalent at Cisco)

This is the third and final post in a series on how Cilium hardens its CI/CD pipeline. Part 1 covered access control and Part 2 covered dependency hardening. This post covers the last layer: keeping CI…


Cloud Native Computing Foundation Announces OpenTelemetry’s Graduation, Solidifying Status as the De Facto Observability Standard

Posted on May 21, 2026

The milestone for OpenTelemetry reflects widespread production adoption and a stable, vendor-neutral observability standard   Key Highlights: MINNEAPOLIS – OBSERVABILITY SUMMIT – May 21, 2026 – The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for…


Ingress NGINX retirement: Experience from end users

Posted on April 2, 2026 | CNCF End User TAB

During last November’s Kubecon + CloudNativeCon North America in Atlanta there was an announcement regarding the retirement of ingress-nginx. As mentioned in the original blog post, existing deployments of Ingress NGINX will continue to function and…


Cloud Native Computing Foundation Announces Kyverno’s Graduation

Posted on March 24, 2026

Kyverno reaches graduation after demonstrating broad enterprise adoption as platform teams adopt declarative governance Key Highlights: KUBECON + CLOUDNATIVECON NORTH EUROPE, AMSTERDAM, The Netherlands – March 24, 2026 – The Cloud Native Computing Foundation® (CNCF®), which…