Kubernetes finishes kpromo rewrite for secure image promotion

The Linux Foundation announced that Kubernetes has completed a rewrite of its kpromo system, modernizing the image promotion supply chain. The update removes the legacy pipeline and enables provenance features by default for all images.

Kubernetes, the popular open-source container orchestration platform, has modernized its image promotion supply chain through a complete rewrite of kpromo, the system responsible for moving images into the registry at github.com/kubernetes/registry.k8s.io. The Linux Foundation shared this update, noting that the legacy pipeline has been fully removed. Newer provenance features are now enabled by default, including SLSA attestation, cosign validation, and keyless signing for all Kubernetes images. The Linux Foundation described this as a critical step for building trust in the supply chain. kpromo plays a key role in ensuring that container images used in Kubernetes deployments meet security standards before entering the official registry. This change aims to enhance security practices across the ecosystem by making advanced verification methods standard. The announcement highlights ongoing efforts to strengthen software supply chain integrity amid rising concerns over vulnerabilities in container images.

Связанные статьи

Photo of Red Hat announcing OpenShift 4.20 at KubeCon, featuring stage presentation with AI and security visuals, and an engaged audience.
Изображение, созданное ИИ

Red Hat announces OpenShift 4.20 at KubeCon

Сообщено ИИ Изображение, созданное ИИ

At KubeCon + CloudNativeCon, Red Hat unveiled OpenShift 4.20, a new version of its platform aimed at unifying enterprise IT from legacy virtual machines to AI workloads. The release emphasizes enhanced security, accelerated AI capabilities, and expanded virtualization support. Additional announcements highlight customer efficiencies and open-source advancements.

The Linux Foundation has announced a significant milestone for the Margo Initiative with the launch of Preview Release 1. This release focuses on improving interoperability in edge application management for industrial settings. It enables vendors to begin prototyping using the initiative's approach.

Сообщено ИИ

A recent CNCF survey reveals that cloud native technologies have become firmly established as core infrastructure in organizations. Kubernetes is widely adopted in production environments, according to the findings. Operational maturity plays a key role in managing AI workloads.

The Linux kernel project has begun using Sashiko, an AI-powered system, to automatically review patches. This agentic, LLM-driven tool is identifying bugs that human reviewers overlooked. The initiative aims to enhance code quality and maintainability.

Сообщено ИИ

SUSE has emphasized the limitations of manual management in modern hybrid and multicloud setups. The company advocates for a unified control plane to simplify operations as infrastructure becomes more distributed. A new guide details deploying SUSE Multi-Linux Manager on Google Cloud.

SUSE has pointed out that high IT costs are often due to complexity in infrastructure. The company suggests that a modern Linux foundation can simplify operations without disruption. This approach allows teams to focus on innovation rather than maintenance issues.

Сообщено ИИ

The Linux kernel project has implemented a new protocol to ensure its survival if creator Linus Torvalds becomes unavailable. Titled the Linux Project Continuity Document, the plan outlines an emergency governance process activated in catastrophic scenarios. This measure addresses long-standing concerns about the project's reliance on a single key figure.

 

 

 

Этот сайт использует куки

Мы используем куки для анализа, чтобы улучшить наш сайт. Прочитайте нашу политику конфиденциальности для дополнительной информации.
Отклонить