Container Security and Governance
How Shopify Governs Containers at Scale with Grafeas and Kritis - Shopify

How Shopify Governs Containers at Scale with Grafeas and Kritis - Shopify

10/12/2017

What this post added

Introduces the use of Grafeas for storing container metadata and Kritis for enforcing deployment policies on Kubernetes. Details how Grafeas answers auditing questions about containers and how Kritis uses signed attestations from authorities to define and enforce deployment policies, ensuring containers meet security controls like build origin, vulnerability scanning, and rootless execution. Mentions integration with kubeaudit for runtime security checks.

Read the original post ↗