DevSecOps
How Container Image Signing Works From Build to Kubernetes Deployment
Container image signing helps DevOps teams verify artifact identity and integrity before deployment, strengthening software supply chain security with signatures, provenance and Kubernetes admission controls ...
Michael Carter | | Artifact Integrity, attestations, CI/CD security, container image signing, container registry, container security, cryptographic signing, deployment policy, DevSecOps, ephemeral runners, image digest, image provenance, keyless signing, Kubernetes admission, Kubernetes security, SBOM, software provenance, software supply chain, supply chain security, trusted delivery
RapidFort Creates Multiple Alliances to Better Secure Cloud-Native Applications
RapidFort, a provider of curated open source container images, has allied with both Wiz and Aqua Security to streamline DevSecOps workflows for organizations building and deploying cloud-native applications. Additionally, RapidFort has inked ...
Production-Safe Security Testing: A Missing Layer in Cloud-Native Application Security
Cloud-native applications keep changing after deployment, making production-safe security testing essential for validating real vulnerabilities, misconfigurations and access-control gaps without disrupting live systems ...
Dharmesh Acharya | | API security, application security, attack surface management, business logic flaws, CI/CD security, cloud native security, cloud security, container security, continuous security testing, DevSecOps, IAM security, microservices security, misconfiguration, non-destructive testing, penetration testing, production security testing, production validation, runtime security, security posture, vulnerability validation
Manifestly Safer, Why Kubernetes Wants Developers to Speak KYAML
KYAML gives Kubernetes developers a stricter, more predictable YAML dialect designed to reduce configuration errors, ambiguity, indentation problems and unexpected type coercion ...
Adrian Bridgwater | | CI/CD, cloud native, cloud native security, cloud-native architecture, configuration management, containers, devops, DevSecOps, Helm, KEP 5295, kubectl, kubernetes, Kubernetes configuration, Kubernetes manifests, Kubernetes security, Kubernetes YAML, KYAML, open source, platform engineering, SIG CLI, YAML, YAML errors
From Controls to Continuous Assurance: Rethinking GRC for Cloud-Native Environments
The standard process of building governance, risk, and compliance (GRC) programs has been straightforward: define a control, document a control, test the control on a regular basis, and generate a report for ...
Echo Acquires Hardened Container Assets from Minimus
Echo today revealed it has acquired technology assets from Minimus, a provider of hardened open source container images, that earlier this week revealed it is shutting down. Those assets will later be ...
Securing North-South Traffic in AKS Using Application Gateway, WAF and AGIC
Secure AKS north-south traffic with Application Gateway, WAF and AGIC, combining Layer 7 protection, end-to-end TLS, private back ends and strong ingress visibility ...
Olaitan Falolu | | AGIC, AKS security, Application Gateway Ingress Controller, application security, Azure Application Gateway, Azure Kubernetes Service, Azure security, cloud native security, DevSecOps, end-to-end TLS, Ingress controller, ingress protection, Kubernetes ingress security, Kubernetes networking, Kubernetes security, Layer 7 security, north-south traffic, private AKS, WAF, web application firewall
Docker Hub vs. Private Registries: Security Tradeoffs
In the race to accelerate software delivery, Docker Hub has become a default starting point for developers and organizations alike. It offers convenience, accessibility, and a vast ecosystem of pre-built images that ...
How Base Images Impact Software Supply Chain Security in Kubernetes
As organizations scale their Kubernetes environments, the software supply chain becomes increasingly complex, interconnected, and vulnerable. One of the most overlooked yet foundational components of this supply chain is the base image ...
Container Runtime Security in Kubernetes: What Teams Overlook
Kubernetes security conversations tend to center on the things that happen on the left-hand side of the process. Scanning images, hardening Dockerfiles, and working with registry access controls all tend to frontload ...

