Chainguard Enforce: Software Supply Chain Security for K8s
Summary
Only half a year ago, founder Kim Lewandowski, co-founder of Chainguard, the zero-trust security company, said, “Supply chain security by default is our mission and making it really easy for developers to do the right thing.” Now with the beta release of Chainguard Enforce, its first product, a native software supply chain solution for Kubernetes workloads, is here. “We’re starting with a very prescriptive set of policies designed for key management and SLSA levels, without a full-blown language.” Moving forward, Chainguard’s developers are also looking into using Configure Unify Execute (CUE) an open source language with a set of APIs for defining policies. Chainguard also claims that it will take less than a day for your DevOps teams to install and configure these build system integrations. As the company said, “We have built this tool with these stakeholders and developers in mind, in the hopes of making the software supply chain more secure by default.” Enforce’s foundation is the open source Sigstore project. It secures software supply chains by creating digital signatures for containerized programs’ building blocks.