These tutorials accompany the presentation Supply Chain Security Tooling
- git
- docker (https://docs.docker.com/engine/install/#desktop)
- kind (https://kind.sigs.k8s.io/docs/user/quick-start/#installation)
- helm (https://helm.sh/docs/intro/install/)
- cosign (https://docs.sigstore.dev/cosign/installation/)
Bonus Dependencies:
- openssl
- rekor-cli (https://docs.sigstore.dev/rekor/installation)
- gitsign (https://docs.sigstore.dev/gitsign/installation)
- cosign - Covers the basics of signing and verifying container images with the
cosign
utility - controller - Install and secure a Kubernetes namespace with the sigstore
policy-controller
- github-action - Use a GitHub Action to build, push, and sign a container while capturing and validating provenance (walkthrough, not a demo)
- gitsign - Secure your code at commit-time by signing commits with an OIDC identity.