Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Supply chain secure software factory reference architecture (Supply Chain Working Group) #679

Closed
2 tasks done
lumjjb opened this issue Jun 1, 2021 · 20 comments
Closed
2 tasks done
Assignees
Labels

Comments

@lumjjb
Copy link
Contributor

lumjjb commented Jun 1, 2021

Communications/Meetings for this issue

A group meets up to discuss this issue as part of the Supply Chain Working Group. To keep in the loop of conversations, please join the slack channel: https://cloud-native.slack.com/archives/C01KL0B4LKC

Description:

Create a working group around an effort to create a reference architecture (backed by an open source implementation) of a Secure Software Factory (SSF) as highlighted in the supply chain paper.

Context: This is a continued effort from the original supply chain working group's work with the Supply Chain Paper. There are various discussions ongoing related to this in #625, #501, #600, Zero-Trust Supply Chains - Google Docs

Impact:

This working group will provide a commonplace for implementors of different communities (SPIRE, in-toto, tekton, sigstore, etc.) to work towards a similar goal of SSF. There are multiple efforts ongoing related to this, and this will help consolidate certain work streams.

Scope:

The scope of this includes architecture discussions and implementation efforts across various communities. The artifact produced from this should be a document laying out the reference architecture of a SSF with an appendix with implementation pointers and examples.

The target audience for this working group are implementors of SSF and contributing members of the underlying SSF components.

Proposed Schedule

Q4 2020

  • [7 Oct] Ready for public comment for sections before prototyping
  • [7 Oct] Cleanup document and open for RFC
  • [11 Oct] Kubecon - Socialize RFC
  • [21 Oct] Introduce new participants from Kubecon and overview of work and direction / levelset
  • [28 Oct] Start discussion/writing on draft prototype design section
  • [11 Nov] Complete draft for prototype design section, start main group discussion
  • [25 Nov] Close main group discussion around prototype design (Thanksgiving, no meeting)
  • [2 Dec- 20 Dec] Start planning and staffing for Supply Chain Ref Arch prototype sections agreed, staffing, getting additional folks/maintainers in
    • Consider other project limitations / work to reach ref arch baseline
  • [20 Dec - 1 Jan 2022] Holidays

Q1 2021

  • PROTOTYPING!!!

Q2 2021

  • SHIP IT!!!

Contributing

To contribute, please refer to the "Contributing" section of the reference architecture document

Contributors

  • Aditya Sirish
  • Aeva Black
  • Alex Floyd Marshall
  • Andres Vega
  • Andrew Block
  • Aradhna Chetal
  • Axel Simon
  • Brandon Lum
  • Brandon Mitchell
  • Dan Pop
  • David A Wheeler
  • Ed Warnicke
  • Emily Fox
  • Ethan Lowman
  • Garry Ing
  • Glaucimar Aguiar
  • Jacques Chester
  • Jason Hall
  • John Kjell
  • Maor Kuriel
  • Marina Moore
  • Matt Moore
  • Michael Lieberman
  • Mike Lieberman
  • Priya Wadhwa
  • Rémy Greinhofer
  • Shripad Nadgowda
  • Trishank Karthik Kuppusamy
@lumjjb lumjjb added proposal common precursor to project, for discussion & scoping triage-required Requires triage labels Jun 1, 2021
@lumjjb
Copy link
Contributor Author

lumjjb commented Jun 1, 2021

Next steps for this issue is nomination of project leads as well as presenting this at a TAG meeting.

Tagging relevant members who may be interested in discussions/project leading.

@jonmuk @dlorenc @lhinds @bobcallaway

@lumjjb lumjjb added supplychain and removed triage-required Requires triage labels Jun 1, 2021
@jonmuk
Copy link
Contributor

jonmuk commented Jun 1, 2021 via email

@TheFoxAtWork
Copy link
Contributor

Does this consider #671 ?
Is the intent to have this be the scope/discussion of the Friday meetings given the notes from this Friday past?

@lumjjb
Copy link
Contributor Author

lumjjb commented Jun 1, 2021

Does this consider #671 ?
Is the intent to have this be the scope/discussion of the Friday meetings given the notes from this Friday past?

It should be considered! This came out of a separate set of discussions from the implementors (some of which are not part of the original paper group). I do agree that this is a natural continuation of the supply chain working group.

@lumjjb lumjjb changed the title [Proposal] Supply chain secure software factory reference architecture (Working Group) [Proposal] Supply chain secure software factory reference architecture (Supply Chain Working Group) Jun 2, 2021
@lumjjb lumjjb added suggestion New suggestion for the CNCF sig-security group that don't fall into an existing category and removed proposal common precursor to project, for discussion & scoping labels Jun 2, 2021
@axelsimon
Copy link
Contributor

Hi @lumjjb, as discussed adding myself here as i'd be interested in helping out on this too.

@priyawadhwa
Copy link

Hi @lumjjb -- I've been working on tekton chains & sigstore recently and would be interested in helping out as well!

@bobcallaway
Copy link

@lumjjb I’m happy to assist as well.

@benlaurie
Copy link

@lumjjb Me too!

@laurentsimon
Copy link

@lumjjb please keep me in the loop too.

@anvega anvega self-assigned this Jun 2, 2021
@anvega
Copy link
Contributor

anvega commented Jun 2, 2021

This is a grand ambitious goal but well worth it.

As its been pointed out, the supply chain workgroup did contemplate for this work to be the follow on to the white paper.

There is a considerable amount of work necessary in order to realize this and we'll need to come up with the right architecture and strategy to get the work done, in addition to all the help that we can get.

@lumjjb
Copy link
Contributor Author

lumjjb commented Jun 2, 2021

Let's discuss this during Friday's supply chain wg meeting, since there's already ongoing discussions there around this. This will be posted in this slack channel https://cloud-native.slack.com/archives/C01KL0B4LKC

@nadgowdas
Copy link

I am working on few technologies in this area and happy to help as well.

@laurentsimon
Copy link

laurentsimon commented Jun 4, 2021

when do you meet and how to join the call? I tried joining the Supply Chain WG zoom meeting with no luck.

@lumjjb
Copy link
Contributor Author

lumjjb commented Jun 4, 2021

@laurentsimon Sorry there was a hick-up with the calendar, the "correct" zoom link was in the slack channel. But we will share the meeting notes about this in a bit.

edit: https://docs.google.com/document/d/1MTM782nluFl4_ybG-fXHmRT2k4bPN18ifdzpUltQQCw/edit#heading=h.ssyq3r9mi3y8

@anvega is going to send out a doodle poll to find a better time for everyone to help define the scope of the reference architecture and the project management aspects (meeting cadences, SW mgmt, GH project board, etc.).

@TheFoxAtWork
Copy link
Contributor

The CNCF calendar has also been updated with the correct Zoom meeting.

@achetal01
Copy link
Contributor

I will like to contribute to the Architecture Effort for Supply chain security

@th3w4y
Copy link

th3w4y commented Jul 1, 2021

@TheFoxAtWork

Attended today's TAG-Security Supply Chain -WG, thank you, I do appreciate all the work I see being done so far, and I would also like to contribute.

@TheFoxAtWork TheFoxAtWork assigned lumjjb and anvega and unassigned anvega Jul 15, 2021
@TheFoxAtWork TheFoxAtWork removed the suggestion New suggestion for the CNCF sig-security group that don't fall into an existing category label Jul 15, 2021
@TheFoxAtWork
Copy link
Contributor

@lumjjb @anvega @danpopSD can you all provide an update to the issue with schedule, progress links etc?

@lumjjb lumjjb added the project work of the group label Aug 12, 2021
@lumjjb lumjjb added this to the STAG Rep: @lumjjb milestone Aug 25, 2021
@TheFoxAtWork
Copy link
Contributor

This issue needs to be updated with a timeline, corresponding milestone deliverables, and list ALL the contributors thus far. This needs updated before KubeCon+CloudNativeCon.

@anvega anvega changed the title [Proposal] Supply chain secure software factory reference architecture (Supply Chain Working Group) [WIP] Supply chain secure software factory reference architecture (Supply Chain Working Group) Jan 19, 2022
@anvega anvega changed the title [WIP] Supply chain secure software factory reference architecture (Supply Chain Working Group) Supply chain secure software factory reference architecture (Supply Chain Working Group) Jan 19, 2022
@lumjjb lumjjb added the Q1-2022 label Feb 23, 2022
@anvega
Copy link
Contributor

anvega commented Jan 9, 2023

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
Status: Done
Development

No branches or pull requests