Kubernetes finishes kpromo rewrite for secure image promotion

The Linux Foundation announced that Kubernetes has completed a rewrite of its kpromo system, modernizing the image promotion supply chain. The update removes the legacy pipeline and enables provenance features by default for all images.

Kubernetes, the popular open-source container orchestration platform, has modernized its image promotion supply chain through a complete rewrite of kpromo, the system responsible for moving images into the registry at github.com/kubernetes/registry.k8s.io. The Linux Foundation shared this update, noting that the legacy pipeline has been fully removed. Newer provenance features are now enabled by default, including SLSA attestation, cosign validation, and keyless signing for all Kubernetes images. The Linux Foundation described this as a critical step for building trust in the supply chain. kpromo plays a key role in ensuring that container images used in Kubernetes deployments meet security standards before entering the official registry. This change aims to enhance security practices across the ecosystem by making advanced verification methods standard. The announcement highlights ongoing efforts to strengthen software supply chain integrity amid rising concerns over vulnerabilities in container images.

관련 기사

Photo of Red Hat announcing OpenShift 4.20 at KubeCon, featuring stage presentation with AI and security visuals, and an engaged audience.
AI에 의해 생성된 이미지

Red Hat announces OpenShift 4.20 at KubeCon

AI에 의해 보고됨 AI에 의해 생성된 이미지

At KubeCon + CloudNativeCon, Red Hat unveiled OpenShift 4.20, a new version of its platform aimed at unifying enterprise IT from legacy virtual machines to AI workloads. The release emphasizes enhanced security, accelerated AI capabilities, and expanded virtualization support. Additional announcements highlight customer efficiencies and open-source advancements.

The Linux Foundation has announced a significant milestone for the Margo Initiative with the launch of Preview Release 1. This release focuses on improving interoperability in edge application management for industrial settings. It enables vendors to begin prototyping using the initiative's approach.

AI에 의해 보고됨

A recent CNCF survey reveals that cloud native technologies have become firmly established as core infrastructure in organizations. Kubernetes is widely adopted in production environments, according to the findings. Operational maturity plays a key role in managing AI workloads.

The Linux kernel project has begun using Sashiko, an AI-powered system, to automatically review patches. This agentic, LLM-driven tool is identifying bugs that human reviewers overlooked. The initiative aims to enhance code quality and maintainability.

AI에 의해 보고됨

SUSE has emphasized the limitations of manual management in modern hybrid and multicloud setups. The company advocates for a unified control plane to simplify operations as infrastructure becomes more distributed. A new guide details deploying SUSE Multi-Linux Manager on Google Cloud.

SUSE has pointed out that high IT costs are often due to complexity in infrastructure. The company suggests that a modern Linux foundation can simplify operations without disruption. This approach allows teams to focus on innovation rather than maintenance issues.

AI에 의해 보고됨

The Linux kernel project has implemented a new protocol to ensure its survival if creator Linus Torvalds becomes unavailable. Titled the Linux Project Continuity Document, the plan outlines an emergency governance process activated in catastrophic scenarios. This measure addresses long-standing concerns about the project's reliance on a single key figure.

 

 

 

이 웹사이트는 쿠키를 사용합니다

사이트를 개선하기 위해 분석을 위한 쿠키를 사용합니다. 자세한 내용은 개인정보 보호 정책을 읽으세요.
거부