Loading…
October 11, 2021
Los Angeles, California + Virtual
View More Details & Registration

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for KubeCon + CloudNativeCon North America 2021 - Los Angeles, CA + Virtual and add this Co-Located event to your registration to participate in these sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Pacific Standard Time (PST), UTC -7. To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date." The schedule is subject to change.


IMPORTANT NOTE: Timing of sessions and room locations are subject to change through Monday, September 13 due to schedule changes that will be made as speakers finalize whether speaking in person or virtually.

Sign up or log in to bookmark your favorites and sync them to your phone or calendar.

Keynote [clear filter]
Monday, October 11
 

9:00am PDT

Welcome and Kickoff! - Dan Lorenc, Chainguard
Speakers
avatar for Dan Lorenc

Dan Lorenc

CEO, Chainguard
Dan has been working on and worrying about containers since 2015 as an engineer and manager.He started projects like MinikubeSkaffold, and Kaniko to make containers easy and fun, then got so worried about the state of OSS supply-chains he partnered up with Kim and others to f... Read More →


Monday October 11, 2021 9:00am - 9:10am PDT
Room 403AB + Online Los Angeles Convention Center - 1201 S. Figueroa Street, Los Angeles, CA 90015
  Keynote

9:10am PDT

Keynote: Approaching the SBOM: Best Practice for Software Supply Chain Security - Daniel Nurmi, Anchore
The software bill of materials (SBOM) has quickly become a critical foundation for software supply chain security. Gaining the ability to see and process the full picture of all software components included in your applications is the first step in preventing vulnerabilities and malware from reaching production systems.

The recent United States Executive Order on Improving the Nation's Cybersecurity details the need for software producers to supply SBOMs, as well as maintaining controls on the provenance of software components and tools. The U.S. NTIA has subsequently released minimum elements for a compliant SBOM. This highlights the important role of an SBOM for open source projects, whether they are incorporated in software applications or used as part of the development toolchain.

Multiple Linux Foundation and CNCF projects including SPDX, In-Toto, and SigStore are providing critical frameworks and specifications designed to advance the security of the software supply chain.

This session will explore best practices for generating SBOMs for both open source projects and software producers, we will share insights and lessons learned from creating SBOMs for CNCF projects using Syft, an open source SBOM generator, and predict ways that we see the role of the SBOM in securing software supply chains evolving over time.

Speakers
DN

Daniel Nurmi

CTO, Anchore Inc.



Monday October 11, 2021 9:10am - 9:20am PDT
Room 403AB + Online Los Angeles Convention Center - 1201 S. Figueroa Street, Los Angeles, CA 90015
  Keynote

9:20am PDT

Keynote: Software Supply Chains for Devops - Aysylu Greenberg, Google
Several recent high-profile security incidents were due to compromised software supply chains. Software Supply Chain is a collective term used to describe the stages of software lifecycle from source to deployment through CI/CD pipelines, and all the static and dynamic analyses in between. In the world of microservices and cloud computing, trust in your company’s supply chain is critical, as most of the tooling and dependencies are from open source and vendor projects. When the code hits production, it’s essential to have enough observability to detect and investigate the problem and get to the root cause and mitigation as quickly as possible. With software supply chain attacks, not only is the newly deployed code under suspicion, but also all the tooling used to produce it becomes a potential attack vector, so an efficient and effective way to verify the integrity of the supply chain is paramount. This talk will discuss what information needs to be collected to allow DevOps to inspect and verify the integrity of the supply chain, the challenges of having the right level of detail to reduce mean-time-to-detection and mean-time-to-understanding, some of the existing solutions and open problems in this space.

Speakers
avatar for Aysylu Greenberg

Aysylu Greenberg

Senior Software Engineer, Google
Aysylu Greenberg is the Tech Lead of GCP Container Analysis, focusing on the software supply chain integrity and security. In her spare time, she ponders the design of systems that deal with inaccuracies, enthusiastically reads CS research papers, and paints.



Monday October 11, 2021 9:20am - 9:30am PDT
Room 403AB + Online Los Angeles Convention Center - 1201 S. Figueroa Street, Los Angeles, CA 90015
  Keynote

9:30am PDT

Keynote: Project Trebuchet: How SolarWinds is Using Open Source to Secure Their Supply Chain in the Wake of the Sunburst Hack - Trevor Rosen, SolarWinds
As you're no doubt aware, SolarWinds was hit in December 2020 with a sophisticated supply chain attack perpetrated by nation state actors. In the months since, they've been working to create an entirely new build system based on a number of CNCF and CDF projects. In this talk, you'll learn about what they're building, why it's necessary, and what it's like to be on the inside when the unthinkable happens.

Speakers
avatar for Trevor Rosen

Trevor Rosen

Principal Architect, SolarWinds
Trevor is a Principal Architect in the SaaS group at SolarWinds. He loves talking about containers, K8s, and infosec. Trevor lives in Austin with his family and too many electric guitars.



Monday October 11, 2021 9:30am - 10:10am PDT
Room 403AB + Online Los Angeles Convention Center - 1201 S. Figueroa Street, Los Angeles, CA 90015
  Keynote

10:30am PDT

Keynote: Security of the Open Source Supply Chain, a Call to Action - Luke Hinds, Red Hat
Open source is everywhere and software is eating the world. However, we now face serious challenges within the security of our software and its supply chain from code commit to production. For this talk, Luke Hinds will outline the current immediate threats and what can be done by us as a community to address the risks we face by harnessing Open Source tooling and open transparent development models.

Speakers
avatar for Luke Hinds

Luke Hinds

Senior Principal Software Engineer, Red Hat
Luke Hinds works within the Emerging Technologies group in Red Hat's CTO office, where he leads a team working on open source security. Luke started the project sigstore, alongside many other OSS security projects. He has held numerous OSS community leadership roles, such as the Kubernetes... Read More →


Monday October 11, 2021 10:30am - 10:40am PDT
Room 403AB + Online Los Angeles Convention Center - 1201 S. Figueroa Street, Los Angeles, CA 90015
  Keynote

5:00pm PDT

Closing Remarks - Dan Lorenc, Chainguard
Speakers
avatar for Dan Lorenc

Dan Lorenc

CEO, Chainguard
Dan has been working on and worrying about containers since 2015 as an engineer and manager.He started projects like MinikubeSkaffold, and Kaniko to make containers easy and fun, then got so worried about the state of OSS supply-chains he partnered up with Kim and others to f... Read More →


Monday October 11, 2021 5:00pm - 5:05pm PDT
Room 403AB + Online Los Angeles Convention Center - 1201 S. Figueroa Street, Los Angeles, CA 90015
  Keynote
 
  • Timezone
  • Filter By Venue Los Angeles, California, USA
  • Filter By Type
  • General Session
  • Keynote
  • Lightning Talk
  • Networking + Break
  • Talk Type

Filter sessions
Apply filters to sessions.