logo

How SIG Release Cooks Trustworthy Artifacts From Raw Source Code

2022-10-26

Authors:   Carlos Panato, Jeremy Rickard, Sascha Grunert, Adolfo García Veytia


Abstract

Have you ever wondered how the Kubernetes source code is turned into artifacts for everyone to use? How do you know you can trust those artifacts? Have you heard about signing things and you're not sure how that fits in with Kubernetes? In this Kubernetes Special Interest Group (SIG) Release update, we will give a quick overview of SIG Release, highlight recent accomplishments, review our updated roadmap and discuss our continued efforts to move toward full SLSA (Supply-chain Levels for Software Artifacts) compliance. As part of this, we will deep dive into efforts to move all aspects of the build process and distribution to community controlled infrastructure and our efforts to expand artifact signing beyond just containers. Finally, we’ll talk about how attendees can become involved in SIG Release. These efforts are exciting and important, but we need your help! We’ll discuss how to contribute to SIG Release tooling, the Release Manager role, and discuss our contributor ladder.

Materials:

Post a comment

Related work

Authors: Carlos Panato, Adolfo García Veytia, Stephen Augustus
2022-05-18

Authors: Nabarun Pal, Verónica López González, Adolfo García Veytia
2021-10-13

Authors: Carlos Panato, Adolfo García Veytia
2023-04-20



Authors: Marko Mudrinić, Verónica López González
2023-04-19