Presenters: @aspanner @hatmarch
Description:
Inspired by the earlier presentation of #501 we have found that the open-source project Ploigos is implementing such an approach which is also based on the DoD DevSecOps ref arch.
The presentation gives a short overview and is then mostly a demo where the Ploigos Software Factory Operator is deployed onto OpenShift in order to build and execute a build factory/pipeline including attestation using Rekor.
Time: ~30minutes
Open Source project in use:
https://github.com/ploigos/ploigos-software-factory-operator
https://github.com/sigstore/rekor
https://github.com/openshift
+others
SIG Representative @matthewflannery
Schedule date 27th April 12pm Sydney Time