Cloud Security Podcast

Kubernetes Security Trends 2024 | Software Supply Chain Security, Zero Trust and AI

Dec 14, 2023
Emily Fox, Red Hat security lead and CNCF TOC chair, discusses Kubernetes security trends. She covers software supply chain visibility, Zero Trust practices like mTLS and SPIFFE, the security challenges of edge deployments, and how AI workloads change provenance and detection needs. Short, focused takes on managed vs self-hosted responsibilities and the evolving specialization in cloud-native security.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Treat Edge Devices As Potentially Compromised

  • Edge devices are often treated as potentially compromised once they leave control.
  • Emily Fox outlines constraints of far/near edge, offline devices, and the need for remote attestation and continuous reattestation before deploying workloads.
ADVICE

Use Lightweight Attestation And Optimize Edge Workloads

  • Reuse cloud-native attestation and lightweight stacks to enable secure edge deployments.
  • Emily Fox cites projects like Keylime and suggests optimizing CPU/carbon footprint so workloads fit constrained edge hosts.
INSIGHT

Apply Supply Chain Thinking To AI Models

  • AI is another workload that needs supply chain assurances about training data, model provenance, and inference confidence.
  • Emily Fox proposes an "AI bill of materials" to trace data sources, training duration, authors, and confidence to reduce hallucination risks.
Get the Snipd Podcast app to discover more snips from this episode
Get the app