Back To Schedule
Tuesday, May 21 • 11:05 - 11:40
Rootless, Reproducible, and Hermetic: Secure Container Build Showdown - Andrew Martin, Control Plane

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
Rootless container image builds (as distinct from rootless runtimes) have crept ever closer with orca-build, BuildKit, and img proving the concept. And they are desperately needed: a build pipeline with an exposed Docker socket can be used by an attacker to escalate privilege - and is probably a backdoor into most Kubernetes-based CI build farms.

With a slew of new rootless tooling emerging including Red Hat’s buildah, Google’s Kaniko, and Uber’s Makisu, will we see build systems that can securely build untrusted Dockerfiles? How are traditional build and packaging requirements like reproducibility or hermetic isolation being approached? In this talk we:
- Compare the strengths and weaknesses of modern container image build tools
- Explore the safety of untrusted image builds
- Live demo attacking container build pipelines
- Chart the history and future of container image build tooling

avatar for Andrew Martin

Andrew Martin

CEO, ControlPlane
Andrew is Founder and CEO of https://control-plane.io, CISO at OpenUK, and co-chair of the CNCF’s Technical Advisory Group for Security. He has an incisive security engineering ethos gained building and destroying high-traffic web applications. Proficient in secure systems development... Read More →

Tuesday May 21, 2019 11:05 - 11:40 CEST
Hall 8.1 G1