You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
decide on the tooling. Not sure what goes here, but there will be a need for an evidence/attestation wharehouse and a policy enforcer. I'd like to use sigstore and kiverno if they fit the bill.
deploy the tooling. using gitops
enhance the pipeline to use the tooling
implement one policy to prove the concept, possibly an image signature verification.
The text was updated successfully, but these errors were encountered:
as a first step, can we discuss what tools we need and how they are going to interact? Let's say for now that we want to sign images. and allow only signed images to be ran.
The text was updated successfully, but these errors were encountered: