‹ Blogs
CNCF Cloud Native Security Whitepaper

Published on
December 01, 2020
Author
Andrew Martin
The CNCF has published a new CNCF Cloud Native Security Whitepaper, which addresses some of the security challenges in deploying a cloud native system, and offers recommendations to CISOs, architects, and developers.
ControlPlane CEO Andrew Martin and Head of Security Rowan Baker authored and contributed to sections of the document, along with numerous other community contributors and reviewers.
Some of the sections containing ControlPlane’s contributions:
Thanks to the sig-security leadership, and multitude of other authors and contributors.
Related blogs

Blog
Internal ≠Isolated (Or Secure): The Argo CD Repo-Server Flaw
An unpatched, unauthenticated RCE in the Argo CD repo-server that can chain into full Kubernetes cluster takeover.
security
threat-modeling
kubernetes
gitops

Blog
Validating Zero Trust: Network Policy Testing with Flux CD and Netassert
security
networking
kubernetes
ci-cd
blue-team
flux-cd
gitops
zero-trust

Blog
Defusing CanisterWorm: How Bun and Deno Secure the JavaScript Supply Chain
TeamPCP’s CanisterWorm is exploiting npm’s postinstall hooks. Learn how modern JavaScript runtimes like Bun and Deno neutralise this threat by default.
supply-chain
security
open-source
threat-modeling
