Container Journal: “Kubernetes 1.25 Update Focuses on Security and Storage”
This week, the Technical Oversight Committee (TOC) for Kubernetes released a Combiner update to the cloud-native platform that adds more than 40 enhancements.
Cloud Native Security Whitepaper version 1.0 audiobook release
Community post from the Security Technical Advisory Group (TAG) In 2020, the Security Technical Advisory Group (TAG) within the CNCF published the initial version of a whitepaper outlining the lifecycle and landscape for cloud native security….
Improving CNCF security posture with independent security audits
When Policy meets Execution Community post by Amir Montazery, Managing Director, Open Source Technology Improvement Fund In this blog post, we present an overview of independent audits conducted at the end of 2021 and first half…
The Cybersecurity Poverty Line and its impact on secure remote access to the cloud
Guest post originally published on the Appaegis blog by Prakash Nagpal What I learned at RSA There was a lot of talk about change, transformation, shifting left, disruption and more at RSA. There was also a…
Project post by KubeEdge maintainers The security of cloud native edge computing has been of concern to many users. It was difficult for users to perform effective security hardening on their edge systems due to no…
Cloud Native Live: Examining Pod Security Admission
Kubernetes v1.22 offered a new built-in admission controller called Pod Security Admission (PSA) meant to replace Pod Security Policies. Join us as we discuss the pros and cons of PSA, and compare it with other alternatives.
OSTIF’s audit of Argo is complete. Critical and high severity security issues found and fixed.
Community post originally published on OSTIF’s blog Open Source Technology Improvement Fund is happy to report the results of yet another security audit, this time of the Argo project. The Argo project is a collection of tools for getting…
2022 Argo external security audit: Lessons learned
Project post cross-posted from the Argo Blog by Michael Crenshaw In early 2022, the Argo team and CNCF began work with Ada Logics to perform a security audit on the four Argo projects. Ada Logics discovered…
OSTIF’s audit of KubeEdge is complete. Multiple security issues found and fixed.
Community post originally published on the OSTIF blog Open Source Technology Improvement Fund (ostif.org) is thrilled to report the results of a security audit of KubeEdge. KubeEdge is an edge computing framework built on top of…
Improving Security by Fuzzing the CNCF landscape
By Chris Aniszczyk (CNCF), Adam Korczynski (Ada Logics), David Korczynski (Ada Logics) In this blog post we present an overview of the state of fuzzing across CNCF projects. This is based on efforts and work that…