SlideShare a Scribd company logo
Secure Supply Chain
Security Engineer - Docker inc.
Ashwini Oruganti
Solutions Architect - Docker inc.
Andy Clemenko
Building a Secure Supply Chain with Docker
Building a Secure Supply Chain with Docker
Building a Secure Supply Chain with Docker
Docker EE
Signing
Scanning
Promotion
• Manual
• Cumbersome
• Multiple sources
Legos?
Fire?
Starting points
store.docker.com
Building a Secure Supply Chain with Docker
Certified
Official
Community
IF?
Automated
Dockerfile
Makes Sense
Build Your Own
Building a Secure Supply Chain with Docker
.gitlab-ci.yml
Dockerfile
app.py
flask.yml
static
templates
Automated builds
Docker EE
Signing
Scanning
Promotion
Developer
or CI
Trusted
Registry
Building a Secure Supply Chain with Docker
Building a Secure Supply Chain with Docker
Building a Secure Supply Chain with Docker
321
docker	trust
Demo
Signing Policy + docker	trust
Docker EE
Signing
Scanning
Promotion
Building a Secure Supply Chain with Docker
Docker EE
Signing
Scanning
Promotion
Image Promotion
! Promotes “blessed” images from one repository
to another
! Repositories each have their own access control
! Images can be re-tagged automatically to a new
tag
! Can be done “manually” or automatically by a
“policy”
dev /
qa /
staging /
prod /
Demo
git commit -sam "updated app.py” && git push
Workflow
Git
Workflow
Git CI
Build/Pull
Push
Workflow
Git CI
Build/Pull
Push
DTR
Private Repo
Scan/Promote
Workflow
Git CI
Build/Pull
Push
CI
Pull & Sign
DTR
Private Repo
Scan/Promote
Workflow
Git CI
Build/Pull
Push
CI
Pull & Sign
DTR
Private Repo
Scan/Promote
DTR
Public Repo
Docker EE
Hosted Demo
● Free 4 Hour Demo

● No Servers Required

● Full Docker EE
Cluster Access
docker.com/trial
https://success.docker.com
https://store.docker.com
Thank You!
@_ashfall_
@aclemenko

More Related Content

What's hot (20)

PDF
Troubleshooting tips from docker support engineers
Docker, Inc.
 
PDF
The Complexity to "Yes" in Analytics Software and the Possibilities with Dock...
Docker, Inc.
 
PDF
5 patterns for success for application transformation
Docker, Inc.
 
PDF
Shipping and Shifting ~100 Apps with Docker EE
Docker, Inc.
 
PDF
How to build your containerization strategy
Docker, Inc.
 
PDF
Docker?!?! But I'm a SysAdmin
Docker, Inc.
 
PPTX
DockerCon EU 2015: Placing a container on a train at 200mph
Docker, Inc.
 
PPTX
Accelerating the Next 10,000 Clouds by Michael Kadera, Intel
Docker, Inc.
 
PDF
Docker Meetup at Docker HQ: Docker Cloud
Docker, Inc.
 
PDF
What's New in Docker
Docker, Inc.
 
PDF
DCSF 19 Building Your Development Pipeline
Docker, Inc.
 
PDF
DCEU 18: Docker Containers in a Serverless World
Docker, Inc.
 
PDF
Evénement Docker Paris: Anticipez les nouveaux business model et réduisez vos...
Docker, Inc.
 
PDF
Docker in Production, Look No Hands! by Scott Coulton
Docker, Inc.
 
PDF
Docker Multi-arch All The Things
Docker, Inc.
 
PDF
DCEU 18: State of the Docker Engine
Docker, Inc.
 
PDF
Advanced Access Control with Docker EE
Docker, Inc.
 
PDF
DockerCon SF 2015: Docker in the New York Times Newsroom
Docker, Inc.
 
PPTX
Chugging Our Own "Craft Brew” – HPE’s Journey Towards Containers-as-a-Service...
Docker, Inc.
 
PDF
Building a Service Delivery Platform - JCICPH 2014
Andreas Rehn
 
Troubleshooting tips from docker support engineers
Docker, Inc.
 
The Complexity to "Yes" in Analytics Software and the Possibilities with Dock...
Docker, Inc.
 
5 patterns for success for application transformation
Docker, Inc.
 
Shipping and Shifting ~100 Apps with Docker EE
Docker, Inc.
 
How to build your containerization strategy
Docker, Inc.
 
Docker?!?! But I'm a SysAdmin
Docker, Inc.
 
DockerCon EU 2015: Placing a container on a train at 200mph
Docker, Inc.
 
Accelerating the Next 10,000 Clouds by Michael Kadera, Intel
Docker, Inc.
 
Docker Meetup at Docker HQ: Docker Cloud
Docker, Inc.
 
What's New in Docker
Docker, Inc.
 
DCSF 19 Building Your Development Pipeline
Docker, Inc.
 
DCEU 18: Docker Containers in a Serverless World
Docker, Inc.
 
Evénement Docker Paris: Anticipez les nouveaux business model et réduisez vos...
Docker, Inc.
 
Docker in Production, Look No Hands! by Scott Coulton
Docker, Inc.
 
Docker Multi-arch All The Things
Docker, Inc.
 
DCEU 18: State of the Docker Engine
Docker, Inc.
 
Advanced Access Control with Docker EE
Docker, Inc.
 
DockerCon SF 2015: Docker in the New York Times Newsroom
Docker, Inc.
 
Chugging Our Own "Craft Brew” – HPE’s Journey Towards Containers-as-a-Service...
Docker, Inc.
 
Building a Service Delivery Platform - JCICPH 2014
Andreas Rehn
 

Similar to Building a Secure Supply Chain with Docker (20)

PPTX
Start tracking your ruby infrastructure
Sergiy Kukunin
 
PPTX
Docker Security workshop slides
Docker, Inc.
 
PDF
Docker for developers
andrzejsydor
 
PDF
Building a Secure App with Docker - Ying Li and David Lawrence, Docker
Docker, Inc.
 
PDF
Docker Security Deep Dive by Ying Li and David Lawrence
Docker, Inc.
 
PDF
Docker Enterprise Edition Overview by Steven Thwaites, Technical Solutions En...
Ashnikbiz
 
PDF
Docker Enterprise Edition: Building a Secure Supply Chain for the Enterprise ...
Docker, Inc.
 
PDF
DCSF 19 Docker Enterprise Platform and Architecture
Docker, Inc.
 
PPTX
Docker Timisoara: Dockercon19 recap slides, 23 may 2019
Radulescu Adina-Valentina
 
PPTX
Docker Roadshow 2016
Docker, Inc.
 
PDF
Introduction to Docker, Devops Virtualization and configuration management
AbhinShyam1
 
PDF
Dockercon EU 2014
Rafe Colton
 
PDF
Accelerate your software development with Docker
Andrey Hristov
 
PPTX
Accelerate your development with Docker
Andrey Hristov
 
PPTX
The Tale of a Docker-based Continuous Delivery Pipeline by Rafe Colton (ModCl...
Docker, Inc.
 
PPTX
Docker Starter Pack
Saeed Hajizade
 
PDF
[@NaukriEngineering] Docker 101
Naukri.com
 
PDF
Docker on Docker
Docker, Inc.
 
PDF
Использование Docker в CI / Александр Акбашев (HERE Technologies)
Ontico
 
PPTX
Docker Overview - AWS Tech Connect - Seattle 10/28
Mike Coleman
 
Start tracking your ruby infrastructure
Sergiy Kukunin
 
Docker Security workshop slides
Docker, Inc.
 
Docker for developers
andrzejsydor
 
Building a Secure App with Docker - Ying Li and David Lawrence, Docker
Docker, Inc.
 
Docker Security Deep Dive by Ying Li and David Lawrence
Docker, Inc.
 
Docker Enterprise Edition Overview by Steven Thwaites, Technical Solutions En...
Ashnikbiz
 
Docker Enterprise Edition: Building a Secure Supply Chain for the Enterprise ...
Docker, Inc.
 
DCSF 19 Docker Enterprise Platform and Architecture
Docker, Inc.
 
Docker Timisoara: Dockercon19 recap slides, 23 may 2019
Radulescu Adina-Valentina
 
Docker Roadshow 2016
Docker, Inc.
 
Introduction to Docker, Devops Virtualization and configuration management
AbhinShyam1
 
Dockercon EU 2014
Rafe Colton
 
Accelerate your software development with Docker
Andrey Hristov
 
Accelerate your development with Docker
Andrey Hristov
 
The Tale of a Docker-based Continuous Delivery Pipeline by Rafe Colton (ModCl...
Docker, Inc.
 
Docker Starter Pack
Saeed Hajizade
 
[@NaukriEngineering] Docker 101
Naukri.com
 
Docker on Docker
Docker, Inc.
 
Использование Docker в CI / Александр Акбашев (HERE Technologies)
Ontico
 
Docker Overview - AWS Tech Connect - Seattle 10/28
Mike Coleman
 
Ad

More from Docker, Inc. (20)

PDF
Containerize Your Game Server for the Best Multiplayer Experience
Docker, Inc.
 
PDF
How to Improve Your Image Builds Using Advance Docker Build
Docker, Inc.
 
PDF
Build & Deploy Multi-Container Applications to AWS
Docker, Inc.
 
PDF
Securing Your Containerized Applications with NGINX
Docker, Inc.
 
PDF
How To Build and Run Node Apps with Docker and Compose
Docker, Inc.
 
PDF
Hands-on Helm
Docker, Inc.
 
PDF
Distributed Deep Learning with Docker at Salesforce
Docker, Inc.
 
PDF
The First 10M Pulls: Building The Official Curl Image for Docker Hub
Docker, Inc.
 
PDF
Monitoring in a Microservices World
Docker, Inc.
 
PDF
COVID-19 in Italy: How Docker is Helping the Biggest Italian IT Company Conti...
Docker, Inc.
 
PDF
Predicting Space Weather with Docker
Docker, Inc.
 
PDF
Become a Docker Power User With Microsoft Visual Studio Code
Docker, Inc.
 
PDF
How to Use Mirroring and Caching to Optimize your Container Registry
Docker, Inc.
 
PDF
Monolithic to Microservices + Docker = SDLC on Steroids!
Docker, Inc.
 
PDF
Kubernetes at Datadog Scale
Docker, Inc.
 
PDF
Labels, Labels, Labels
Docker, Inc.
 
PDF
Using Docker Hub at Scale to Support Micro Focus' Delivery and Deployment Model
Docker, Inc.
 
PDF
Build & Deploy Multi-Container Applications to AWS
Docker, Inc.
 
PDF
From Fortran on the Desktop to Kubernetes in the Cloud: A Windows Migration S...
Docker, Inc.
 
PDF
Developing with Docker for the Arm Architecture
Docker, Inc.
 
Containerize Your Game Server for the Best Multiplayer Experience
Docker, Inc.
 
How to Improve Your Image Builds Using Advance Docker Build
Docker, Inc.
 
Build & Deploy Multi-Container Applications to AWS
Docker, Inc.
 
Securing Your Containerized Applications with NGINX
Docker, Inc.
 
How To Build and Run Node Apps with Docker and Compose
Docker, Inc.
 
Hands-on Helm
Docker, Inc.
 
Distributed Deep Learning with Docker at Salesforce
Docker, Inc.
 
The First 10M Pulls: Building The Official Curl Image for Docker Hub
Docker, Inc.
 
Monitoring in a Microservices World
Docker, Inc.
 
COVID-19 in Italy: How Docker is Helping the Biggest Italian IT Company Conti...
Docker, Inc.
 
Predicting Space Weather with Docker
Docker, Inc.
 
Become a Docker Power User With Microsoft Visual Studio Code
Docker, Inc.
 
How to Use Mirroring and Caching to Optimize your Container Registry
Docker, Inc.
 
Monolithic to Microservices + Docker = SDLC on Steroids!
Docker, Inc.
 
Kubernetes at Datadog Scale
Docker, Inc.
 
Labels, Labels, Labels
Docker, Inc.
 
Using Docker Hub at Scale to Support Micro Focus' Delivery and Deployment Model
Docker, Inc.
 
Build & Deploy Multi-Container Applications to AWS
Docker, Inc.
 
From Fortran on the Desktop to Kubernetes in the Cloud: A Windows Migration S...
Docker, Inc.
 
Developing with Docker for the Arm Architecture
Docker, Inc.
 
Ad

Recently uploaded (20)

PPTX
MuleSoft MCP Support (Model Context Protocol) and Use Case Demo
shyamraj55
 
PPTX
Future Tech Innovations 2025 – A TechLists Insight
TechLists
 
PDF
Agentic AI lifecycle for Enterprise Hyper-Automation
Debmalya Biswas
 
PDF
Staying Human in a Machine- Accelerated World
Catalin Jora
 
PPTX
The Project Compass - GDG on Campus MSIT
dscmsitkol
 
PDF
What’s my job again? Slides from Mark Simos talk at 2025 Tampa BSides
Mark Simos
 
PDF
The Rise of AI and IoT in Mobile App Tech.pdf
IMG Global Infotech
 
PDF
Future-Proof or Fall Behind? 10 Tech Trends You Can’t Afford to Ignore in 2025
DIGITALCONFEX
 
PDF
“Voice Interfaces on a Budget: Building Real-time Speech Recognition on Low-c...
Edge AI and Vision Alliance
 
PDF
“NPU IP Hardware Shaped Through Software and Use-case Analysis,” a Presentati...
Edge AI and Vision Alliance
 
PDF
The 2025 InfraRed Report - Redpoint Ventures
Razin Mustafiz
 
PDF
UPDF - AI PDF Editor & Converter Key Features
DealFuel
 
PDF
Automating Feature Enrichment and Station Creation in Natural Gas Utility Net...
Safe Software
 
PDF
Go Concurrency Real-World Patterns, Pitfalls, and Playground Battles.pdf
Emily Achieng
 
PPTX
Mastering ODC + Okta Configuration - Chennai OSUG
HathiMaryA
 
PDF
“Squinting Vision Pipelines: Detecting and Correcting Errors in Vision Models...
Edge AI and Vision Alliance
 
PDF
AI Agents in the Cloud: The Rise of Agentic Cloud Architecture
Lilly Gracia
 
PPTX
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
PDF
Peak of Data & AI Encore AI-Enhanced Workflows for the Real World
Safe Software
 
PDF
Newgen Beyond Frankenstein_Build vs Buy_Digital_version.pdf
darshakparmar
 
MuleSoft MCP Support (Model Context Protocol) and Use Case Demo
shyamraj55
 
Future Tech Innovations 2025 – A TechLists Insight
TechLists
 
Agentic AI lifecycle for Enterprise Hyper-Automation
Debmalya Biswas
 
Staying Human in a Machine- Accelerated World
Catalin Jora
 
The Project Compass - GDG on Campus MSIT
dscmsitkol
 
What’s my job again? Slides from Mark Simos talk at 2025 Tampa BSides
Mark Simos
 
The Rise of AI and IoT in Mobile App Tech.pdf
IMG Global Infotech
 
Future-Proof or Fall Behind? 10 Tech Trends You Can’t Afford to Ignore in 2025
DIGITALCONFEX
 
“Voice Interfaces on a Budget: Building Real-time Speech Recognition on Low-c...
Edge AI and Vision Alliance
 
“NPU IP Hardware Shaped Through Software and Use-case Analysis,” a Presentati...
Edge AI and Vision Alliance
 
The 2025 InfraRed Report - Redpoint Ventures
Razin Mustafiz
 
UPDF - AI PDF Editor & Converter Key Features
DealFuel
 
Automating Feature Enrichment and Station Creation in Natural Gas Utility Net...
Safe Software
 
Go Concurrency Real-World Patterns, Pitfalls, and Playground Battles.pdf
Emily Achieng
 
Mastering ODC + Okta Configuration - Chennai OSUG
HathiMaryA
 
“Squinting Vision Pipelines: Detecting and Correcting Errors in Vision Models...
Edge AI and Vision Alliance
 
AI Agents in the Cloud: The Rise of Agentic Cloud Architecture
Lilly Gracia
 
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
Peak of Data & AI Encore AI-Enhanced Workflows for the Real World
Safe Software
 
Newgen Beyond Frankenstein_Build vs Buy_Digital_version.pdf
darshakparmar
 

Building a Secure Supply Chain with Docker