Git Product home page Git Product logo

sig-security's Introduction

CNCF Special Interest Group for Security (SIG-Security)

Objective

SIG-Security facilitates collaboration to discover and produce resources which enable secure access, policy control and safety for operators, administrators, developers, and end-users across the cloud native ecosystem.

Background

“Cloud Native” is open source cloud computing for applications — a complete trusted toolkit for modern architectures (CNCF presentation). There are multiple projects which address key parts of the problem of providing access controls and addressing safety concerns. Each of these adds value, yet for these technical solutions to be capable of working well together and manageable to operate they will need a minimal shared context of what defines a secure system architecture.

Vision

There is a future where operators, administrators and developers feel confident creating new cloud native applications. They use cloud technologies with clear understanding of risks and the ability to validate that their security policy decisions are reflected in deployed software.

We envision that there could exist an ecosystem of tools that can simplify the experience of cloud native operators, administrators and developers, including:

  1. System security architecture that understands and accommodates the ever growing heterogeneity of systems and provides a framework to protect resources and data while servicing their users
  2. Common vocabulary and open source libraries that make it easy for developers to create and deploy apps that meet system security requirements
  3. Common libraries and protocols that enable people to reason about the security of the system, such as auditing and explainability features.

Governance

SIG-Security charter outlines the scope of our group activities, as part of our governance process which details how we work.

Members

Related Groups

History

Communications

Anyone is welcome to join our open discussions of WG projects and share news related to the group's mission and charter. Much of the work of the group happens outside of WG meetings and we encourage project teams to share progress updates or post questions in these channels:

Meeting Time

The Security SIG group meets every Wednesday at 10:00am PT (USA Pacific):

Join: https://zoom.us/my/cncfsigsecurity

One tap mobile:

  • +16465588656,,7375677271# US (New York)
  • +16699006833,,7375677271# US (San Jose)

Dial by your location:

  • +1 646 558 8656 US (New York)
  • +1 669 900 6833 US (San Jose)
  • 877 369 0926 US Toll-free
  • 855 880 1246 US Toll-free Meeting ID: 737 567 7271 Find your local number: https://zoom.us/u/alwlmxlNn

In Person Meetings

Please let us know if you are going and if you are interested in attending (or helping to organize!) an in-person meetup. Create a github issue for an event and add to list below:

  • KubeCon + CloudNativeCon, San Diego, CA - Nov 18 – 21, 2019 - [issue#128]

Past Events

Meeting Minutes

sig-security's People

Contributors

ultrasaurus avatar dshaw avatar pragashj avatar justincappos avatar lumjjb avatar rachelmyers avatar lizrice avatar rficcaglia avatar quiqie avatar caniszczyk avatar thefoxatwork avatar izgeri avatar santiagotorres avatar ashutosh-narkar avatar joshuagl avatar justincormack avatar leodido avatar fntlnz avatar sublimino avatar tsandall avatar kbpawlowski avatar mhausenblas avatar omerlh avatar pbnj avatar rae42 avatar raravena80 avatar simar7 avatar sreetummidi avatar zparnold avatar chasemp avatar

Watchers

James Cloos avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.