Charter

As agreed to by the TSC and documented in the approved Nephio Community Document, this SIG group focuses on security of code, images, deployment, and the runtime environment; development of CRDs, Operators, related tooling & reference Implementation; and packaging and security verification of components of Nephio.

Community

Most activity is coordinated over the #sig-security slack channel.

For details on meetings and links to other resources see the SIG Security wiki page.

Subprojects

Considerations for the SIG as a group:

Opportunity for the SIG: Differentiate Nephio as a "Secure Telco Automation Framework".

Following high-level security focus areas could be considered:

Nephio Security focus areas

For each subproject, we list a lead and the scope of the subproject, as well as the primary skills involved in participating in that subproject. As an open community, we do not "require" any specific skills for contributors to participate in the subproject. We hope to find ways for anyone to contribute, and to build the necessary skills. However, it can be useful to list the primary skills and areas of expertise involved in each group, to help people decide where they may wish to participate.

Code/Repo/Release security

Subproject Lead: TBA

Scope

For every code repo in nephio-project github organization, it would be important to follow code/repo security scanning best practices. Depending on the development language used, the tooling might differ for individual repos. It would be better to use common github actions across all repos in the organization that would internally use appropriate secret tokens defined as part of github secrets.

This subproject will focus on:

Primary Skills

Deployment Security

Subproject Lead: TBA

Scope

Primary Skills

Runtime Security

Subproject Lead: TBA

Scope Once the workloads are deployed in the target environments, securing the workloads at runtime becomes crucial. Following runtime security use-cases needs to be taken into consideration:

Primary Skills

K8s Security Operator

Subproject Lead: TBA

This group will study and propose how a k8s security operator could improve and maintain the security posture of the target depoyment. The scope includes:

Primary Skills

Ensuring Zero Trust Security for Nephio

Subproject Lead: TBA

This group will study and propose how the Nephio components can achieve Zero Trust security and subsequently the full lifecycle to maintain the Zero Trust security posture. The scope includes:

Primary Skills

References:

  1. Linux Foundation Security Framework