Search a title or topic

Over 20 million podcasts, powered by 

Player FM logo
Artwork

Content provided by Viktor Petersson. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Viktor Petersson or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Dustin Kirkland on Chainguard, Zero-CVE Containers, and Supply Chain Security

59:15
 
Share
 

Manage episode 466636015 series 3621860
Content provided by Viktor Petersson. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Viktor Petersson or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
In this episode of Nerding Out with Viktor, host Viktor Petersson sits down with Dustin Kirkland from Chainguard for an illuminating discussion on modern supply chain security and container hardening. Drawing from his rich experience across tech giants like IBM, Red Hat, Canonical, and Google, Dustin shares invaluable insights into the evolution of container security and the critical importance of maintaining secure infrastructure.

The conversation delves deep into Chainguard's innovative approach to building minimal, hardened container images directly from source code. Dustin explains their groundbreaking Zero-CVE initiative, demonstrating how continuous rolling updates and careful dependency management can dramatically reduce vulnerability exposure. Through practical examples and real-world scenarios, he illustrates the delicate balance between security, functionality, and maintainability in modern container deployments.

Viktor and Dustin explore the intricate world of Software Bills of Materials (SBOMs), diving into how attestations and digital signatures through tools like Sigstore and Cosign create a robust chain of trust. The discussion illuminates the critical role these technologies play in guaranteeing software provenance and enabling rapid vulnerability patching across complex deployments.

The episode also tackles the challenges of navigating stringent compliance requirements such as FedRAMP and HIPAA, with Dustin sharing practical strategies for maintaining security without sacrificing agility. The conversation extends to the nuances of open source licensing and the future landscape of infrastructure security, offering listeners valuable insights into maintaining secure, modern systems in an increasingly complex technological environment.

Whether you're a security professional, container enthusiast, or technology leader, this episode provides essential knowledge about the future of supply chain security and container hardening. Don't miss this comprehensive exploration of how organizations can build and maintain secure infrastructure in today's rapidly evolving technology landscape.

]]>
  continue reading

34 episodes

Artwork
iconShare
 
Manage episode 466636015 series 3621860
Content provided by Viktor Petersson. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Viktor Petersson or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://podcastplayer.com/legal.
In this episode of Nerding Out with Viktor, host Viktor Petersson sits down with Dustin Kirkland from Chainguard for an illuminating discussion on modern supply chain security and container hardening. Drawing from his rich experience across tech giants like IBM, Red Hat, Canonical, and Google, Dustin shares invaluable insights into the evolution of container security and the critical importance of maintaining secure infrastructure.

The conversation delves deep into Chainguard's innovative approach to building minimal, hardened container images directly from source code. Dustin explains their groundbreaking Zero-CVE initiative, demonstrating how continuous rolling updates and careful dependency management can dramatically reduce vulnerability exposure. Through practical examples and real-world scenarios, he illustrates the delicate balance between security, functionality, and maintainability in modern container deployments.

Viktor and Dustin explore the intricate world of Software Bills of Materials (SBOMs), diving into how attestations and digital signatures through tools like Sigstore and Cosign create a robust chain of trust. The discussion illuminates the critical role these technologies play in guaranteeing software provenance and enabling rapid vulnerability patching across complex deployments.

The episode also tackles the challenges of navigating stringent compliance requirements such as FedRAMP and HIPAA, with Dustin sharing practical strategies for maintaining security without sacrificing agility. The conversation extends to the nuances of open source licensing and the future landscape of infrastructure security, offering listeners valuable insights into maintaining secure, modern systems in an increasingly complex technological environment.

Whether you're a security professional, container enthusiast, or technology leader, this episode provides essential knowledge about the future of supply chain security and container hardening. Don't miss this comprehensive exploration of how organizations can build and maintain secure infrastructure in today's rapidly evolving technology landscape.

]]>
  continue reading

34 episodes

Tutti gli episodi

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Listen to this show while you explore
Play