DevOps and Docker Talk: Cloud Native Interviews and Tooling

Chainguard: Building Secure Container Images


Listen Later

Bret and Nirmal are joined by Dan Lorenc from Chainguard to walk them through Chainguard's approach to building secure, minimal container images for popular open source software.

šŸ™Œ My next course is coming soon! I've opened the waitlist for those wanting to go deep in GitHub Actions for DevOps and AI automation in 2025. I'm so thrilled to announce this course. The waitlist allows you to quickly sign up for some content updates, discounts, and more as I finish building the course. https://learn.bretfisher.com/waitlistšŸ¾

They discuss why it is important to have secure and minimal container images. Dan explains how Chainguard helps remove the pain of CVEs, laggy software updates and patches and much more. Chainguard is now available also on Docker Hub.

They spend the first part of the show talking about the week's big news: the XZ supply chain attack, and Dan was the best man to explain it. They also touch on CVEs, things you can do to reduce the attack surface, SLSA, and more during this jam-packed show.

There's a video version you can watch on YouTube

ā˜…Topicsā˜…
Chainguard Website
Vulnerability Management Certification course
True Cost of Vulnerability Management
Chainguard Images
Chainguard on Docker Hub Announcement

Creators & Guests

  • Cristi Cotovan - Editor
  • Beth Fisher - Producer
  • Bret Fisher - Host
  • Nirmal Mehta - Host
  • Dan Lorenc - Guest
    • (00:00) - Intro
  • (05:14) - Dan's Take on the XZ Hack
  • (14:59) - Chainguard Distro Creation
  • (21:21) - Chainguard in Docker Hub Announcement
  • (24:26) - Free Images vs Private Images
  • (26:27) - Zero CVE Approach
  • (28:33) - Ways to Reduce Attack Surfaces
  • (39:56) - Chainguard Academy
  • (41:08) - Real Time Antivirus Malware Scanner
  • (43:52) - Google Distro Lists Worth Using
  • (45:56) - Chainguard for Buildpacks
  • (46:20) - SLSA
  • (56:08) - What's Next for Chainguard?
  • (56:52) - Getting Started with Chainguard

  • You can also support my free material by subscribing to my YouTube channel and my weekly newsletter at bret.news!

    Grab the best coupons for my Docker and Kubernetes courses.
    Join my cloud native DevOps community on Discord.
    Grab some merch at Bret's Loot Box
    Homepage bretfisher.com

    ...more
    View all episodesView all episodes
    Download on the App Store

    DevOps and Docker Talk: Cloud Native Interviews and ToolingBy Bret Fisher

    • 4.6
    • 4.6
    • 4.6
    • 4.6
    • 4.6

    4.6

    54 ratings


    More shows like DevOps and Docker Talk: Cloud Native Interviews and Tooling

    View all
    The Knowledge Project by Shane Parrish

    The Knowledge Project

    2,691 Listeners

    6 Minute English by BBC Radio

    6 Minute English

    1,754 Listeners

    Learning English Conversations by BBC Radio

    Learning English Conversations

    1,043 Listeners

    The Diary Of A CEO with Steven Bartlett by DOAC

    The Diary Of A CEO with Steven Bartlett

    8,580 Listeners

    Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

    Kubernetes Podcast from Google

    182 Listeners

    Day Two DevOps by Packet Pushers

    Day Two DevOps

    15 Listeners

    DevOps Paradox by Darin Pope & Viktor Farcic

    DevOps Paradox

    25 Listeners

    Adventures in DevOps by Will Button, Warren Parad

    Adventures in DevOps

    18 Listeners

    Think Fast Talk Smart: Communication Techniques by Matt Abrahams, Think Fast Talk Smart

    Think Fast Talk Smart: Communication Techniques

    798 Listeners

    All-In with Chamath, Jason, Sacks & Friedberg by All-In Podcast, LLC

    All-In with Chamath, Jason, Sacks & Friedberg

    9,932 Listeners

    Coaching Real Leaders by Harvard Business Review / Muriel Wilkins

    Coaching Real Leaders

    676 Listeners

    The Ezra Klein Show by New York Times Opinion

    The Ezra Klein Show

    15,938 Listeners

    The Foreign Affairs Interview by Foreign Affairs Magazine

    The Foreign Affairs Interview

    445 Listeners

    The Rest Is Politics: US by Goalhanger

    The Rest Is Politics: US

    2,198 Listeners

    Agentic DevOps by Bret Fisher

    Agentic DevOps

    2 Listeners