Virtualization Review: “Cloud Native Security Survey: Kubernetes Defaults ‘Too Open'”
Respondents to a cloud native security survey said default settings for the Kubernetes container orchestration platform are “too open.” That problem hinders secure production deployments and will require effort and maturity to solve, according to a…
7 Ways to mitigate your SaaS application security risks
Originally published on the Msys Technologies blog If you’re a SaaS entrepreneur or you’re looking to build a SaaS application, in that case, you may already be aware of the fact that there is a new…
As the cloud native computing world prepares to gather in Los Angeles for a mixed virtual and in-person KubeCon + CloudNativeCon event, the conference tag of “Resilience Realized” has taken on special meaning.
Open sourcing the SPIFFE/SPIRE security audit
A few years back, CNCF began performing and open sourcing third-party security audits for projects to improve the overall security of our ecosystem. These audits have helped identify security issues, from general weaknesses to critical vulnerabilities,…
CNCF On-Demand Webinar: Policy as code – what Helm developers need to know about security
Modern Kubernetes applications are often composed of components packaged in the form of Helm charts. These modular applications help teams deliver innovation to market faster than ever. However, building applications from components that may not have…
Cloud Native Security Day Europe 2021
Cloud Native Security Day is designed to foster collaboration, discussion and knowledge sharing of discuss cloud native security projects and how to best use these to address security challenges and opportunities. The goal is not just…
CNCF paper defines best practices for supply chain security
New paper demonstrates an actionable approach to architecting a secure supply chain amidst an increase in cyber attacks SAN FRANCISCO, Calif. – May 14, 2021 – The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems…
Evaluating your Supply Chain Security
Last December, as we were all counting down the days until 2020 was no more, FireEye posted an announcement that caused various beveragewares across the world to fall and shatter on the floor: some sort of…
Never should you ever in Kubernetes part 2: Kubernetes security mistakes
Guest post originally published on Fairwinds’s blog by Danielle Cook, technical writer at Fairwinds As we outlined in our first post in this series, there are some things that you should simply never, ever do in Kubernetes. Corey…
SiliconANGLE: “Diversity, security and end-user contributions are focal points of KubeCon 2021”
Improving diversity in tech communities is an increasingly popular debate today, and it is no different in the open-source ecosystem. The topic is always at the forefront of the Cloud Native Computing Foundation, and one of…