finos / community

FINOS Community, Project and SIG wide collaboration space
http://community.finos.org
66 stars 28 forks source link

DevOps Mutualization - Structuring conversations around SDLC and Iterating the different types of evidence that needs to be produced #55

Closed mcleo-d closed 4 years ago

mcleo-d commented 4 years ago

Description

This issue has been created to capture and iterate the compliance evidence required by banking and fintech DevOps teams.

DevOps Mutualization Meeting Notes

Date and Time : Thursday 30th July @ 1pm ET / 6pm BST - https://github.com/finos/community/issues/52#issuecomment-669343645

mcleo-d commented 4 years ago

Hi @peterrhysthomas

Can you upload the Software Supply Chain with Grafeas and Kritis slide you presented as part of the meeting. It would be great to have as reference material for the future?

Cheers 🚀

James.

peterrhysthomas commented 4 years ago

Grafeas provides the metadata store with Kritis performing the enforcement of the metadata at deploy time into Kubernetes. For more details see the InfoQ presentation and slides. These are used within the GCP Binary Authorisation process. An alternative (which looks similar at first glance) is Open Policy Agent.

mcleo-d commented 4 years ago

Hey all - The following Evidence Lake Document has been created in the DevOps Mutualization Project on GitHub to break the conversation out of this issue and place it in project where people can add their own documents and edit existing ones through pull requests.

https://github.com/finos-labs/devops-mutualization/blob/master/docs/evidence-lake.md

Let me know if you have further questions.

James.

mcleo-d commented 4 years ago

This issue has now moved into the DevOps Mutualization Project and can be found here -> https://github.com/finos-labs/devops-mutualization/issues/4