DevOps and Docker Talk: Cloud Native Interviews and Tooling

Software Supply Chain Security with Chainguard


Listen Later

Bret is joined by two Chainguard co-founders, CEO Dan Lorenc and Head of Product, Kim Lewandowski, to break down the ins and outs of supply chain security and talk about Chainguard's approach to securing it. We dive into tools, including their new Wolfi Linux distro.

We first talk about what that even is, because it's a buzzword right now, and not everyone's on the same page on what securing your supply chain even means in the world of software. Then we jump into base images for containers, and their project Wolfi. We talk a lot about Wolfi in this episode, because it has the potential to change how we build our containers.

Streamed live on YouTube on October 13, 2022.


Unedited live recording of this show on YouTube (Ep #188)

Topics★
Chainguard Website
Chainguard Twitter
Chainguard Academy
Wolfi
Wolfi-based images
Sigstore

★Dan Lorenc★
Dan Lorenc on Twitter
Dan Lorenc on Linkedin

★Kim Lewandowski★
Kim Lewandowski on Twitter
Kim Lewandowski on Linkedin

Join my Community
New live course on CI automation and gitops deployments
Best coupons for my Docker and Kubernetes courses
Chat with us and fellow students on our Discord Server DevOps Fans

Homepage bretfisher.com

  • (00:00) - DDT MAIN
  • (00:04) - Intro
  • (00:54) - Custom intro
  • (02:51) - Main show
  • (03:04) - Introductions
  • (03:24) - How did Chainguard get started?
  • (04:23) - What is a supply chain?
  • (06:30) - First Security Things
  • (08:55) - The article and the base image
  • (12:02) - Wolfi elevator pitch
  • (14:49) - How do packages get into Wolfi?
  • (18:49) - How do Wolfi packages work
  • (21:57) - Chainguard Enforce
  • (26:43) - Question about in-toto
  • (29:08) - Preventing unsigned images in production
  • (30:44) - Blocking vulnerable dependencies with policies
  • (31:39) - Scanning on servers
  • (34:02) - Question
  • (35:53) - Question
  • (37:50) - Getting started with Wolfi
  • (39:57) - Where are they on Github (demo?)
  • (40:50) - Question about vex
  • (43:13) - What else?
  • (43:40) - Chainguard Academy
  • (45:24) - Professional services
  • (49:32) - Wrapping up
  • (49:56) - Outro

  • You can also support my free material by subscribing to my YouTube channel and my weekly newsletter at bret.news!

    Grab the best coupons for my Docker and Kubernetes courses.
    Join my cloud native DevOps community on Discord.
    Grab some merch at Bret's Loot Box
    Homepage bretfisher.com

    ...more
    View all episodesView all episodes
    Download on the App Store

    DevOps and Docker Talk: Cloud Native Interviews and ToolingBy Bret Fisher

    • 4.6
    • 4.6
    • 4.6
    • 4.6
    • 4.6

    4.6

    53 ratings


    More shows like DevOps and Docker Talk: Cloud Native Interviews and Tooling

    View all
    Hanselminutes with Scott Hanselman by Scott Hanselman

    Hanselminutes with Scott Hanselman

    377 Listeners

    Software Engineering Radio - the podcast for professional software developers by se-radio@computer.org

    Software Engineering Radio - the podcast for professional software developers

    266 Listeners

    The Changelog: Software Development, Open Source by Changelog Media

    The Changelog: Software Development, Open Source

    285 Listeners

    The Cloudcast by Massive Studios

    The Cloudcast

    153 Listeners

    Thoughtworks Technology Podcast by Thoughtworks

    Thoughtworks Technology Podcast

    41 Listeners

    Talk Python To Me by Michael Kennedy

    Talk Python To Me

    586 Listeners

    Software Engineering Daily by Software Engineering Daily

    Software Engineering Daily

    629 Listeners

    AWS Podcast by Amazon Web Services

    AWS Podcast

    200 Listeners

    Data Engineering Podcast by Tobias Macey

    Data Engineering Podcast

    140 Listeners

    Syntax - Tasty Web Development Treats by Wes Bos & Scott Tolinski - Full Stack JavaScript Web Developers

    Syntax - Tasty Web Development Treats

    990 Listeners

    Kubernetes Podcast from Google by Abdel Sghiouar, Kaslin Fields

    Kubernetes Podcast from Google

    180 Listeners

    Self-Hosted by Jupiter Broadcasting

    Self-Hosted

    135 Listeners

    The Stack Overflow Podcast by The Stack Overflow Podcast

    The Stack Overflow Podcast

    63 Listeners

    The Real Python Podcast by Real Python

    The Real Python Podcast

    137 Listeners

    2.5 Admins by The Late Night Linux Family

    2.5 Admins

    89 Listeners