Closed mcleo-d closed 4 years ago
Hi @peterrhysthomas
Can you upload the Software Supply Chain with Grafeas and Kritis slide you presented as part of the meeting. It would be great to have as reference material for the future?
Cheers 🚀
James.
Grafeas provides the metadata store with Kritis performing the enforcement of the metadata at deploy time into Kubernetes. For more details see the InfoQ presentation and slides. These are used within the GCP Binary Authorisation process. An alternative (which looks similar at first glance) is Open Policy Agent.
Hey all - The following Evidence Lake Document has been created in the DevOps Mutualization Project on GitHub to break the conversation out of this issue and place it in project where people can add their own documents and edit existing ones through pull requests.
https://github.com/finos-labs/devops-mutualization/blob/master/docs/evidence-lake.md
Let me know if you have further questions.
James.
This issue has now moved into the DevOps Mutualization Project and can be found here -> https://github.com/finos-labs/devops-mutualization/issues/4
Description
This issue has been created to capture and iterate the compliance evidence required by banking and fintech DevOps teams.
DevOps Mutualization Meeting Notes
Date and Time : Thursday 30th July @ 1pm ET / 6pm BST - https://github.com/finos/community/issues/52#issuecomment-669343645