The talk discusses the issue of supply chain controls in CD GitOps automation and proposes a solution to ensure integrity and tamper-proof deployments.
- CD GitOps lacks supply chain controls needed for integrity and tamper-proof deployments
- Properly instrumented CD GitOps process can provide verification of source assets with cluster enforcement of signatures and policy permissions
- Keyless signing via Sigstore and intersecting control points throughout GitOps can obtain accurate cryptographic signing of source assets and transparency of configuration provenance
- Admission controller such as Integrity Shield can validate pipeline integrity