Demo: Chainguard’s Enforce for Cloud Native Application Security

The New Stack · Intermediate ·🚀 Entrepreneurship & Startups ·3y ago

Key Takeaways

The video demonstrates Chainguard's Enforce, a continuously verifying policy enforcement engine for cloud native application security, showcasing its features and capabilities in identifying vulnerabilities and enforcing security policies. Enforce integrates with various tools such as Sigstore, Kubernetes, and cloud providers like Google Cloud, AWS, and Cloud Run.

Full Transcript

[Music] and actions there used to be this advertisement that was like popular in the northwest for Rainier Beer they go Rainier Beer Jesus ever ring a bell no okay but I want some now so advertising works okay because I was thinking [Laughter] [Applause] nice that's just I'm offended that's what I thought of so we're going to look at a demo from chain guard and you're Eddie zanesque I am hello hello Eddie and you're a software engineer I am so what are we going to look at so today I'm going to show you chain Garden Force which is our continuously verifying policy enforcement engine for all things containers and supply chain security okay great let's take a look yeah so what are we looking at right now so we're looking at the enforced dashboard and we can see that I have a single cluster that's already set up uh installed into enforce so who's this for who would be looking at this yeah so this is for anyone who is concerned about security of their containers right so security Engineers application evidence uh platform Engineers okay so kind of people in different roles but they want to be able to get it kind of get a glimpse what exactly are we looking at like so if I'm an engineer I'm looking at this what am I looking at I'm looking at the policy compliance I'm looking at what else am I looking at here yeah so this is our overview dashboard okay so this is like quickly at a glance I can see I have a single staging cluster installed I can see kind of a breakdown of the different packages that are running okay and I can see that some of my images 11 out of 32 are compliant and I have a bit a bit failing right now ah okay and these are policies that you can either pull from a catalog or you can craft yourself okay to enforce all sorts of different things okay so we have two failed policies we have a policy compliance of 34 yeah what does that tell them that tells them that they got a bit of work ahead of them yeah I would think so right so I can show you we can take a look at this single cluster here and here I can see those policies and what they're matching and what's failing so these are all the containers that are actually running inside my cluster uh and the really cool thing my favorite part about enforce is we can see the breakdown of all the packages of all these different workloads why is that your favorite because the hardest part about dealing with something for like log for Shell was figuring out what workloads you had were vulnerable okay and we give you that view with a searchable interface that you can go from taking weeks to figure out however long it takes you to type in a word was that pretty important that development for y'all to have this aspect to it yeah that must have been we built the tool that we wanted to use as Engineers ourselves um because what were the what were the tools like beforehand what were you trying what are you trying to do yeah the tools it was all by hand yeah when Cisco was talking to Congress about dealing with log for Shell in the first place they they talked about how it took them x amount of time I think it was like two weeks to come up with a plan to figure out what they had that was vulnerable oh wow that's a long time that's just to figure out a plan to figure out what we're vulnerable right because they they're shipping so many different products so many different routers so many different firmwares yeah um and so that's kind of my favorite part about this is we hopefully cut that down from two weeks to a few seconds here okay that's interesting so I can show you here so the packages I can see that I have some Maven packages running you can see that log4j is actually registered there I can see some Alpine packages so this is like the um openssl version for Alpine so I can see the version and then I can actually drill down and find out what workloads that's running with so one of the the things they had at Google is a term called build Horizon and it was uh kind of like an encapsulation of a bunch of different security for your your production workloads but the one that we're focused on here was uh the artifact age so how long this artifact has been since it's been built and so you can actually have an enforcement policy here that says anything that's older than 30 days I want to flag and fail because maybe you should do a full rebuild to get some OS updates or something and so that's just this policy here I can see that quite a few of the images are failing because they just haven't been rebuilt in 30 days um the other thing I want to show you is we've heard from a lot of our our customers that you know they have a team that might be spinning up a new cluster that's not already enrolled in in force and um kind of like they they want to keep tabs on new clusters as they're created and so we actually have a new feature that we're rolling out called Discovery and so I can do a chain CTL clusters Discovery and give it a provider flag of gke and Cloud run so it's not just kubernetes it's actually workloads that are running in AWS cloud and ECS and eks gcp a bunch of other places and so this is going to slurp in my Google Cloud credentials and so that's what we're looking at the credentials yeah well I have a trust relationship set up so I can see that it found two other clusters that are eligible in my gcp account so this is my production cluster and then this is actually my cloud run environment okay and so I can tell it to go in and enroll those and we'll see back on the dashboard here that we're going to have two new clusters show up so you can continuously run this as your engineers and your your platform teams are creating new clusters and maybe they're testing things out they just have to be enrolled exactly and they don't have to enroll themselves which is the magic part okay moving the burden from them having to sign up and add an agent or something to their cluster I imagine that's something that is helpful to have automated because otherwise you're just waiting kind of for that yeah to happen I would certainly be running it on a continuous job yeah and you can see that there it's going to ingest all those new clusters and all those new images it's going to recalculate some of the failing stuff we can see that the new production cluster has some other packages running so I have a bunch of go applications there should also be some node.js ones in here so we can detect any type of workload and pull up their s-bomb and show you across all of your different languages that your teams are using so you're not just restricted to one language uh here's the npm packages right so I can see all my NVM packages and their versions another cool view is looking at the workloads so I can break this down and see that I have tecton running and tecton has a couple different packages that are running as well and then another policy that I have is tecton must be signed right so we integrate heavily with Sig store and we can enforce that we want certain identities to be signing the images that are running in your cluster so it's actually I can tell that some of these images from tecton aren't actually signed and we can flag on that so now we're looking at it and I said the violations are 14 and the cluster is one the violations would be how are you defining violations so violations are going to be the uh the images that are failing this particular policy and this policy says Hey I want these uh this is actually a public key that we're checking for but it could be any sort of signing Authority or identity okay and then the last thing I wanted to show you was we have a concept of enforcement okay so let's say that we have this policy created for to prevent log for Shell right so we don't want log for Shell introduced to our environment again we and so long trying to clean it up and make sure everything was up to date that we don't want developers to deploy a vulnerable version and so that's what this policy shows here it's got the vulnerable versions listed here it's kind of a big list but what this is going to do is it's going to check inside of that metadata that ships with all those containers that are built and it's going to find which ones are vulnerable and so I've actually gone and I've enabled enforcement on a particular namespace we've designed and forced to be gradually rolled out so you don't have to start by blocking everything you can start with a like an observed phase where you could see what's going on and slowly opt into enforcement on different workloads so let's say that I'm a application developer and I'm going to deploy a vulnerable version of log4j that I don't know is maybe in this image so I've got a demo image here that has that vulnerable version in this cluster this namespace is opted in for enforcement and if we see that I run this it's going to evaluate that image pull that metadata see that it was actually built with a vulnerable version it's going to deny it so right there I can prevent any sort of vulnerability that I know about that I have a policy for for being reintroduced back into the cluster uh and so we have this policy catalog I'm not sure if I mentioned it but we have some of those pre-created policies and that log for J image uh the lock for Shell policy is one but we've tried to make this really easy for users to get up to speed and start with sort of like a springboard to draft their own policies so that's that's the chain Guardian Force in a nutshell well thanks so much Eddie I appreciate the demo yeah thanks for coming by thanks for having me if you like this video please give us a thumbs up and if you'd like to see more videos like this you can always subscribe to our YouTube channel we're on all the major social media platforms you can always find us at the newstack.io we hope to see you soon foreign [Music]

Original Description

Chainguard’s Enforce, a continuously verifying policy enforcement engine for all things containers and supply chain security, was one of the key demos we presented at CloudNative SecurityCon in Seattle. Who benefits from using Enforce? “This is for anyone who is concerned about the security of their containers. So, security engineers, application engineers, and platform engineers,” said Eddie Zaneski, Staff DevRel + OSS Engineer at Chainguard. Zaneski said that the hardest part about dealing with something like Log for Shell was figuring out which of your workloads are vulnerable. Enforce gives you that view, he said: “And we give you that view with a searchable interface that you can go from taking weeks to figure out however long it takes you to type in a word.” Check out the New Stack article “Gorilla Toolkit Open Source Project Becomes Abandonware” featuring Zaneski and Chainguard’s Dan Luring. https://thenewstack.io/gorilla-toolkit-open-source-project-becomes-abandonware/ And, Chainguard founder Dan Lorenc shares his startup journey in the TNS article “The Stone Ages of Open Source Security”. https://thenewstack.io/the-stone-ages-of-open-source-security/ Product Demo Website: https://www.chainguard.dev/chainguard-enforce
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from The New Stack · The New Stack · 0 of 60

← Previous Next →
1 What's Next for the Cloud Foundry Foundation in 2017 with Executive Director Abby Kearns
What's Next for the Cloud Foundry Foundation in 2017 with Executive Director Abby Kearns
The New Stack
2 How Unikernels Can Better Defend against DDoS Attacks
How Unikernels Can Better Defend against DDoS Attacks
The New Stack
3 Weaveworks is Bringing Horizontal Scaling to Prometheus
Weaveworks is Bringing Horizontal Scaling to Prometheus
The New Stack
4 TNS Analysts Thanksgiving Special: The Evolution of Kubernetes and the Container Ecosystem
TNS Analysts Thanksgiving Special: The Evolution of Kubernetes and the Container Ecosystem
The New Stack
5 How Rancher Labs is Seeing Kubernetes Put to Work in Production
How Rancher Labs is Seeing Kubernetes Put to Work in Production
The New Stack
6 SAP Tests Kubernetes for Cloud-Native Enterprise Software Deployments
SAP Tests Kubernetes for Cloud-Native Enterprise Software Deployments
The New Stack
7 Event Marketing for Today's Developer Evangelists and Community Managers
Event Marketing for Today's Developer Evangelists and Community Managers
The New Stack
8 NodeSource Introduces Certified Modules to Improve Node.js Security
NodeSource Introduces Certified Modules to Improve Node.js Security
The New Stack
9 How Lightstep is Illuminating the Case for Distributed Tracing
How Lightstep is Illuminating the Case for Distributed Tracing
The New Stack
10 How OpenStack Aims to be More Inclusive without being Exclusive
How OpenStack Aims to be More Inclusive without being Exclusive
The New Stack
11 How Shuttlecloud Saves Time and Money by Monitoring with Prometheus
How Shuttlecloud Saves Time and Money by Monitoring with Prometheus
The New Stack
12 Creating Analytics-Driven Solutions for Operational Visibility
Creating Analytics-Driven Solutions for Operational Visibility
The New Stack
13 Understanding the Application Pattern for Effective Monitoring
Understanding the Application Pattern for Effective Monitoring
The New Stack
14 Building On Docker's Native Monitoring Functionality
Building On Docker's Native Monitoring Functionality
The New Stack
15 The Importance of Having Visibility Into Containers
The Importance of Having Visibility Into Containers
The New Stack
16 How Getting Your Project in the CNCF Just Got Easier
How Getting Your Project in the CNCF Just Got Easier
The New Stack
17 Tectonic Summit Pancake Breakfast: How to Sell Kubernetes to the Hypervisor-Minded
Tectonic Summit Pancake Breakfast: How to Sell Kubernetes to the Hypervisor-Minded
The New Stack
18 The Buzz at Tectonic Summit 2016 in New York City
The Buzz at Tectonic Summit 2016 in New York City
The New Stack
19 Bringing Clarity to the Future of Node.js Modules
Bringing Clarity to the Future of Node.js Modules
The New Stack
20 How FluentD Can Help Monitor Microservice Architectures Through Unified Logging
How FluentD Can Help Monitor Microservice Architectures Through Unified Logging
The New Stack
21 Reshaping Front End Development with Warehouse.ai
Reshaping Front End Development with Warehouse.ai
The New Stack
22 2016 Year End Wrap-Up: Discussing Docker, OpenStack, and Open Source
2016 Year End Wrap-Up: Discussing Docker, OpenStack, and Open Source
The New Stack
23 Here's Why You Should Build a Robot Using Node.JS: Because You Can
Here's Why You Should Build a Robot Using Node.JS: Because You Can
The New Stack
24 How the Node.js Foundation is Utilizing Participatory Governance Models
How the Node.js Foundation is Utilizing Participatory Governance Models
The New Stack
25 Set Up an MongoDB Replica Set in Less Than an Hour Using Bitnami Packages
Set Up an MongoDB Replica Set in Less Than an Hour Using Bitnami Packages
The New Stack
26 Determining Who Bears the Burden of Ensuring NPM Module Security
Determining Who Bears the Burden of Ensuring NPM Module Security
The New Stack
27 How Intel Snap uses Telemetry and Kubernetes to Drive Enterprise Efficiency
How Intel Snap uses Telemetry and Kubernetes to Drive Enterprise Efficiency
The New Stack
28 How the NFL Scored a Touchdown with its Open Source React Framework Wildcat
How the NFL Scored a Touchdown with its Open Source React Framework Wildcat
The New Stack
29 Aporeto CEO Dimitri Stiliadis: When it Comes to Security, Context is King
Aporeto CEO Dimitri Stiliadis: When it Comes to Security, Context is King
The New Stack
30 The Buzz at Node.JS Interactive
The Buzz at Node.JS Interactive
The New Stack
31 Why Going Serverless Doesn't Mean 'No Ops'
Why Going Serverless Doesn't Mean 'No Ops'
The New Stack
32 How Node.js is Transforming Today's Enterprises
How Node.js is Transforming Today's Enterprises
The New Stack
33 JJ Asghar Interview
JJ Asghar Interview
The New Stack
34 How Capital One is Using APIs to Streamline Auto Financing
How Capital One is Using APIs to Streamline Auto Financing
The New Stack
35 SXSW 2017: How Machine Learning Differs From Regular Programming
SXSW 2017: How Machine Learning Differs From Regular Programming
The New Stack
36 SXSW 2017: Data-Driven Applications with Capital One DevExchange's Hydrograph
SXSW 2017: Data-Driven Applications with Capital One DevExchange's Hydrograph
The New Stack
37 SXSW 2017: How Good Engineers Make Bad Business Decisions
SXSW 2017: How Good Engineers Make Bad Business Decisions
The New Stack
38 CloudNativeCon & KubeCon EU Pancake Breakfast 2017: Kubernetes and the Multi-Cloud
CloudNativeCon & KubeCon EU Pancake Breakfast 2017: Kubernetes and the Multi-Cloud
The New Stack
39 CNCF Executive Director Dan Kohn: What's Next for CNCF in 2017
CNCF Executive Director Dan Kohn: What's Next for CNCF in 2017
The New Stack
40 Exploring the Latest Container Runtime Projects in the CNCF
Exploring the Latest Container Runtime Projects in the CNCF
The New Stack
41 Exploring the Future of the Kubernetes Ecosystem
Exploring the Future of the Kubernetes Ecosystem
The New Stack
42 Kubernetes and Continuous Deployment
Kubernetes and Continuous Deployment
The New Stack
43 Kris Nova of Deis at CouldNativecon/Kubecon in Berlin
Kris Nova of Deis at CouldNativecon/Kubecon in Berlin
The New Stack
44 Docker's Quest for Simplicity with the Evolution of Containerd
Docker's Quest for Simplicity with the Evolution of Containerd
The New Stack
45 Developers First: The Cloud Foundry Service Broker API and Kubernetes
Developers First: The Cloud Foundry Service Broker API and Kubernetes
The New Stack
46 Mapping the Future of CoreOS's rkt in the CNCF
Mapping the Future of CoreOS's rkt in the CNCF
The New Stack
47 Red Hat and Dell EMC: Two Perspectives from DockerCon
Red Hat and Dell EMC: Two Perspectives from DockerCon
The New Stack
48 Capital One Opened its APIs to Third-Party Developers — Here’s What They Learned
Capital One Opened its APIs to Third-Party Developers — Here’s What They Learned
The New Stack
49 SUSE Joins the CNCF, Brings Kubernetes to OpenStack Cloud 7
SUSE Joins the CNCF, Brings Kubernetes to OpenStack Cloud 7
The New Stack
50 How Capital One Brings Open Source To The  Banking Industry
How Capital One Brings Open Source To The Banking Industry
The New Stack
51 OSCON Is Coming Back To Portland, A Show Wrapup With Co-Chair Kelsey Hightower
OSCON Is Coming Back To Portland, A Show Wrapup With Co-Chair Kelsey Hightower
The New Stack
52 Dev Or Ops Doesn’t Matter, You Need Observability
Dev Or Ops Doesn’t Matter, You Need Observability
The New Stack
53 Taking The Next Steps In Developing An Open Source Culture
Taking The Next Steps In Developing An Open Source Culture
The New Stack
54 SXSW 2017: How Capital One Became Technology-First With Open Source
SXSW 2017: How Capital One Became Technology-First With Open Source
The New Stack
55 Apcera   Old Apps Spanning New Clouds
Apcera Old Apps Spanning New Clouds
The New Stack
56 Provenance: The Peace of Mind Chef Habitat Seeks to Deliver
Provenance: The Peace of Mind Chef Habitat Seeks to Deliver
The New Stack
57 InSpec: Human Readable, Automated Compliance
InSpec: Human Readable, Automated Compliance
The New Stack
58 The Evolution of SAP HANA Express
The Evolution of SAP HANA Express
The New Stack
59 Women Engineers Who Inspire And Never Give Up
Women Engineers Who Inspire And Never Give Up
The New Stack
60 Three Perspectives on the Evolution of Container Security
Three Perspectives on the Evolution of Container Security
The New Stack

This video demonstrates the capabilities of Chainguard's Enforce in securing cloud native applications, highlighting its features and integrations with various tools and platforms. By watching this video, viewers can learn how to design and implement secure cloud native applications using Enforce. The video also covers the importance of supply chain security and vulnerability management in cloud native applications.

Key Takeaways
  1. Configure Enforce to monitor cloud native application security
  2. Set up policy enforcement to detect and flag vulnerabilities
  3. Integrate Enforce with Sigstore for signing and identity verification
  4. Use Enforce to discover new clusters and enroll them automatically
  5. Implement enforcement policies to deny deployment of vulnerable versions
💡 Chainguard's Enforce provides a continuously verifying policy enforcement engine for cloud native application security, allowing developers to identify and flag vulnerabilities in real-time, and enforce security policies to protect against potential threats.

Related Reads

📰
Why More SPV Managers Are Choosing SPV Hub Over Carta
SPV managers are choosing SPV Hub over Carta due to its tailored features and pricing for repeat deal flow, making it a more suitable option for their needs.
Medium · Startup
📰
Nuclear Turbines raises £15M for compact reactors it says could undercut fossil fuels
Nuclear Turbines raises £15M to develop compact nuclear reactors that could be cheaper than fossil fuels
The Next Web AI
📰
I Didn’t Want to Build Another Grocery App. I Wanted to Solve a Local Problem.
Learn how to identify local problems and build solutions that matter, rather than following trends like quick commerce
Medium · Startup
📰
The Exploration Company in talks to raise $300M at a $2B valuation
The Exploration Company, a Munich-based startup, is in talks to raise $300M at a $2B valuation to build Europe's first reusable space capsule
The Next Web AI
Up next
Watch this before applying for jobs as a developer.
Tech With Tim
Watch →