‹ Blogs
CNCF Cloud Native Security Whitepaper

Published on
December 01, 2020
Author
Andrew Martin
The CNCF has published a new CNCF Cloud Native Security Whitepaper, which addresses some of the security challenges in deploying a cloud native system, and offers recommendations to CISOs, architects, and developers.
ControlPlane CEO Andrew Martin and Head of Security Rowan Baker authored and contributed to sections of the document, along with numerous other community contributors and reviewers.
Some of the sections containing ControlPlane’s contributions:
Thanks to the sig-security leadership, and multitude of other authors and contributors.
Related blogs

Blog
Sovereign Signing: A Self-Hosted Supply Chain with OpenBao, Cosign, and Flux CD
A fully self-hosted software supply chain signing pipeline (OpenBao holds the key, Cosign signs, Flux CD verifies) with no public cloud KMS and no public Sigstore infrastructure.
supply-chain
security
gitops
flux-cd
open-source
kubernetes

Blog
Internal ≠Isolated (Or Secure): The Argo CD Repo-Server Flaw
An unpatched, unauthenticated RCE in the Argo CD repo-server that can chain into full Kubernetes cluster takeover.
security
threat-modeling
kubernetes
gitops

Blog
Validating Zero Trust: Network Policy Testing with Flux CD and Netassert
security
networking
kubernetes
ci-cd
blue-team
flux-cd
gitops
zero-trust
