2024-09-17 Meeting notes

 Date

Sep 17, 2024

 Participants

  • @Rahul

  • @ved ratan

  • @Prashant

  • @barun1024

  • Thiago Navarro

 Goals

  •  

 Discussion topics

Time

Item

Presenter

Notes

Time

Item

Presenter

Notes

 

IaC scanning report

@ved ratan

  • Report Analysis

  • Raising issues to the wider team?

Include a misconfigurations detector in Nephio · Issue #808 · nephio-project/nephio

checkov => scan the whole catalog package => prioritize the findings => Take the findings back to SIG-Automation => Fix some of those findings ourselves in SIG-Security?



Updates on Workload Identity

@Prashant

Workload Identity reconciler integration using SPIFFE by PrimalPimmy · Pull Request #809 · nephio-project/nephio
Initiating Workload Identity with Spire by PrimalPimmy · Pull Request #84 · nephio-project/catalog

Redhat COP demo in progress (this would allow us to use k8s resources to create vault policies).

 

 

 

 

 

 

 

 

 Action items

 Decisions