Join us

ContentUpdates and recent posts about Sigstore..
Link
@faun shared a link, 1 year, 2 months ago
FAUN.dev()

On How We Moved to Kubernetes

Migrating fromAWS ECStoAWS EKS? Beats the bark out of those pesky spot instance disruptions, but introduces a new player: the complexity monster namedKubernetes. Bigger, faster, cheaper—if you know the dance steps. Juggling CPUs in Kubernetes feels like herding caffeinated cats. EnterKarpenterto sav.. read more  

Link
@faun shared a link, 1 year, 2 months ago
FAUN.dev()

Uber’s Journey to Ray on Kubernetes: Ray Setup

Uber enhanced its machine learning platform by migrating workloads to Kubernetes in early 2024. The migration aimed to solve pain points such as manual resource management, inefficient resource utilization, and inflexible capacity planning. The architecture designed included federated resource manag.. read more  

Link
@faun shared a link, 1 year, 2 months ago
FAUN.dev()

KubeCon Europe: How Google Will Evolve Kubernetes in the AI Era

Googlehas hatched a cunning plan: turnKubernetesinto the go-to choice for AI/ML workloads. It’s outgrowing its “just for containers” phase. In the AI explosion, everyone suddenly wants Kubernetes—who knew? To stay ahead, Google’s jazzing up its cloud offerings with slicker performance, scalability t.. read more  

KubeCon Europe: How Google Will Evolve Kubernetes in the AI Era
Link
@faun shared a link, 1 year, 2 months ago
FAUN.dev()

Recyling a OnePlus 6T into a Kubernetes Node

Connected a 7-year-old OnePlus 6T as a Kubernetes node in my homelab—tagged on "8" cores, 6GB RAM—but postmarketOS kernel didn’t have nftables' numgen!Wrestled with manual kernel compilation and untangled DNS snafus, but now the project's chugging along mighty fine... read more  

Recyling a OnePlus 6T into a Kubernetes Node
Link
@faun shared a link, 1 year, 2 months ago
FAUN.dev()

CNPG Recipe 17 - PostgreSQL In-Place Major Upgrades

CloudNativePG 1.26storms the scene, making PostgreSQL upgrades a breeze inside Kubernetes. It slashes the usual chaos. Minimal downtime threatens, but what's life without a little thrill?.. read more  

CNPG Recipe 17 - PostgreSQL In-Place Major Upgrades
Link
@faun shared a link, 1 year, 2 months ago
FAUN.dev()

Automated Testing for Terraform, Docker, Packer, Kubernetes, and More

Automated tests crush infrastructure anxiety. Use tools likeTerratestto deploy, validate, and clean up—all without a stealth deployment... read more  

Automated Testing for Terraform, Docker, Packer, Kubernetes, and More
Link
@faun shared a link, 1 year, 2 months ago
FAUN.dev()

Introducing kro: Kube Resource Orchestrator

TheKube Resource Orchestrator (kro)dreams big by letting you turn complex Kubernetes APIs into elegant, singleResourceGroupCRDs. Think of it as Kubernetes without the migraines—dependencies and configurations quietly managed in the background. An AWS experiment still cooking, it's not quite ready fo.. read more  

Introducing kro: Kube Resource Orchestrator
Link
@faun shared a link, 1 year, 2 months ago
FAUN.dev()

How autoscaling took down my application..!!

A glitch in the autoscaling settings skewed the NEGs, cramming them into a single AZ. Boom. Next thing you know, pods flounder and the app goes belly-up... read more  

How autoscaling took down my application..!!
Link
@faun shared a link, 1 year, 2 months ago
FAUN.dev()

This Open Source Tool Lets You Build Your Own LMS on Kubernetes

Canvas LMS + Kubernetes:DeployKomposeto morph Docker configs into sleekKubernetesresources. Dive deep into LTI 1.3's superior integration.Instructure's hosted instances miss out on this magic trick. Self-host to unlock the full experience... read more  

Link
@faun shared a link, 1 year, 2 months ago
FAUN.dev()

My Unifi Gateway just learned to do BGP!

BGP setup needs an autonomous system.For iBGP, keep the AS consistent across peers. Go wild with private numbers like64512for your internal playground.Unifi runs FRR for routing,but don’t expect shiny graphics. You're stuck with config uploads. Old-school control freaks might secretly rejoice... read more  

Sigstore is an open source initiative designed to make software artifact signing and verification simple, automatic, and widely accessible. Its primary goal is to improve software supply chain security by enabling developers and organizations to cryptographically prove the origin and integrity of the software they build and distribute.

At its core, sigstore removes many of the traditional barriers associated with code signing. Instead of managing long-lived private keys manually, sigstore supports keyless signing, where identities are issued dynamically using OpenID Connect (OIDC) providers such as GitHub Actions, Google, or Microsoft. This dramatically lowers operational complexity and reduces the risk of key compromise.

The sigstore ecosystem is composed of several key components:

- Cosign: A tool for signing, verifying, and storing signatures for container images and other artifacts. Signatures are stored alongside artifacts in OCI registries, rather than embedded in them.

- Fulcio: A certificate authority that issues short-lived X.509 certificates based on OIDC identities, enabling keyless signing.

- Rekor: A transparency log that records signing events in an append-only, tamper-evident ledger. This provides public auditability and detection of suspicious or malicious signing activity.

Together, these components allow anyone to verify who built an artifact, when it was built, and whether it has been tampered with, using publicly verifiable cryptographic proofs. This aligns closely with modern supply chain security practices such as SLSA (Supply-chain Levels for Software Artifacts).

sigstore is widely adopted in the cloud-native ecosystem and integrates with tools like Kubernetes, container registries, CI/CD pipelines, and package managers. It is commonly used to sign container images, Helm charts, binaries, and SBOMs, and is increasingly becoming a baseline security requirement for production software delivery.

The project is governed by the OpenSSF (Open Source Security Foundation) and supported by major industry players.