Secure Supply Chain
Security Engineer - Docker inc.
Ashwini Oruganti
Solutions Architect - Docker inc.
Andy Clemenko
Building a Secure Supply Chain with Docker
Building a Secure Supply Chain with Docker
Building a Secure Supply Chain with Docker
Docker EE
Signing
Scanning
Promotion
• Manual
• Cumbersome
• Multiple sources
Legos?
Fire?
Starting points
store.docker.com
Building a Secure Supply Chain with Docker
Certified
Official
Community
IF?
Automated
Dockerfile
Makes Sense
Build Your Own
Building a Secure Supply Chain with Docker
.gitlab-ci.yml
Dockerfile
app.py
flask.yml
static
templates
Automated builds
Docker EE
Signing
Scanning
Promotion
Developer
or CI
Trusted
Registry
Building a Secure Supply Chain with Docker
Building a Secure Supply Chain with Docker
Building a Secure Supply Chain with Docker
321
docker	trust
Demo
Signing Policy + docker	trust
Docker EE
Signing
Scanning
Promotion
Building a Secure Supply Chain with Docker
Docker EE
Signing
Scanning
Promotion
Image Promotion
! Promotes “blessed” images from one repository
to another
! Repositories each have their own access control
! Images can be re-tagged automatically to a new
tag
! Can be done “manually” or automatically by a
“policy”
dev /
qa /
staging /
prod /
Demo
git commit -sam "updated app.py” && git push
Workflow
Git
Workflow
Git CI
Build/Pull
Push
Workflow
Git CI
Build/Pull
Push
DTR
Private Repo
Scan/Promote
Workflow
Git CI
Build/Pull
Push
CI
Pull & Sign
DTR
Private Repo
Scan/Promote
Workflow
Git CI
Build/Pull
Push
CI
Pull & Sign
DTR
Private Repo
Scan/Promote
DTR
Public Repo
Docker EE
Hosted Demo
● Free 4 Hour Demo

● No Servers Required

● Full Docker EE
Cluster Access
docker.com/trial
https://success.docker.com
https://store.docker.com
Thank You!
@_ashfall_
@aclemenko

More Related Content

PDF
Containerizing Hardware Accelerated Applications
PDF
Docker ee an architecture and operations overview
PDF
Use Docker to Deliver Cognitive Services Running Cross Platform and Multi Clo...
PDF
Building your production tech stack for docker container platform
PDF
Demystifying container connectivity with kubernetes in docker
PPTX
Learning the Alphabet: A/B, CD and [E-Z] in the Docker Datacenter by Brett Ti...
PDF
Considerations for operating docker at scale
PDF
Packaging software for the distribution on the edge
Containerizing Hardware Accelerated Applications
Docker ee an architecture and operations overview
Use Docker to Deliver Cognitive Services Running Cross Platform and Multi Clo...
Building your production tech stack for docker container platform
Demystifying container connectivity with kubernetes in docker
Learning the Alphabet: A/B, CD and [E-Z] in the Docker Datacenter by Brett Ti...
Considerations for operating docker at scale
Packaging software for the distribution on the edge

What's hot (20)

PDF
Troubleshooting tips from docker support engineers
PDF
The Complexity to "Yes" in Analytics Software and the Possibilities with Dock...
PDF
5 patterns for success for application transformation
PDF
Shipping and Shifting ~100 Apps with Docker EE
PDF
How to build your containerization strategy
PDF
Docker?!?! But I'm a SysAdmin
PPTX
DockerCon EU 2015: Placing a container on a train at 200mph
PPTX
Accelerating the Next 10,000 Clouds by Michael Kadera, Intel
PDF
Docker Meetup at Docker HQ: Docker Cloud
PDF
What's New in Docker
PDF
DCSF 19 Building Your Development Pipeline
PDF
DCEU 18: Docker Containers in a Serverless World
PDF
Evénement Docker Paris: Anticipez les nouveaux business model et réduisez vos...
PDF
Docker in Production, Look No Hands! by Scott Coulton
PDF
Docker Multi-arch All The Things
PDF
DCEU 18: State of the Docker Engine
PDF
Advanced Access Control with Docker EE
PDF
DockerCon SF 2015: Docker in the New York Times Newsroom
PPTX
Chugging Our Own "Craft Brew” – HPE’s Journey Towards Containers-as-a-Service...
PDF
Building a Service Delivery Platform - JCICPH 2014
Troubleshooting tips from docker support engineers
The Complexity to "Yes" in Analytics Software and the Possibilities with Dock...
5 patterns for success for application transformation
Shipping and Shifting ~100 Apps with Docker EE
How to build your containerization strategy
Docker?!?! But I'm a SysAdmin
DockerCon EU 2015: Placing a container on a train at 200mph
Accelerating the Next 10,000 Clouds by Michael Kadera, Intel
Docker Meetup at Docker HQ: Docker Cloud
What's New in Docker
DCSF 19 Building Your Development Pipeline
DCEU 18: Docker Containers in a Serverless World
Evénement Docker Paris: Anticipez les nouveaux business model et réduisez vos...
Docker in Production, Look No Hands! by Scott Coulton
Docker Multi-arch All The Things
DCEU 18: State of the Docker Engine
Advanced Access Control with Docker EE
DockerCon SF 2015: Docker in the New York Times Newsroom
Chugging Our Own "Craft Brew” – HPE’s Journey Towards Containers-as-a-Service...
Building a Service Delivery Platform - JCICPH 2014
Ad

Similar to Building a Secure Supply Chain with Docker (20)

PDF
DCEU 18: Building Your Development Pipeline
PDF
Gitlab ci, cncf.sk
PPTX
Docker e git lab
PPTX
Patterns & Antipatterns in Docker Image Lifecycle
PDF
Common primitives in Docker environments
PDF
Setting up CI/CD pipeline with Kubernetes and Kublr step-by-step
PDF
Setting up CI/CD Pipeline with Kubernetes and Kublr step by-step
PDF
Deploy Angular to the Cloud (ngBucharest)
PPTX
PittsburgJUG_Cloud-Native Dev Tools: Bringing the cloud back to earth
PDF
Production sec ops with kubernetes in docker
PPTX
Build, Publish, Deploy and Test Docker images and containers with Jenkins Wor...
PDF
What is Git | What is GitHub | Git Tutorial | GitHub Tutorial | Devops Tutori...
PPTX
Deploying R for Production - SRUG
PDF
Experts Live Switzerland 2017 - Automatisierte Docker Release Pipeline mit VS...
PDF
CICD_1670665418.pdf
PDF
Jenkins vs GitLab CI
PDF
Building Slack's internal developer platform as a product.pdf
PDF
Better Operations into the Cloud
PDF
Continuos Integration and Delivery: from Zero to Hero with TeamCity, Docker a...
PDF
CI/CD with Jenkins and Docker - DevOps Meetup Day Thailand
DCEU 18: Building Your Development Pipeline
Gitlab ci, cncf.sk
Docker e git lab
Patterns & Antipatterns in Docker Image Lifecycle
Common primitives in Docker environments
Setting up CI/CD pipeline with Kubernetes and Kublr step-by-step
Setting up CI/CD Pipeline with Kubernetes and Kublr step by-step
Deploy Angular to the Cloud (ngBucharest)
PittsburgJUG_Cloud-Native Dev Tools: Bringing the cloud back to earth
Production sec ops with kubernetes in docker
Build, Publish, Deploy and Test Docker images and containers with Jenkins Wor...
What is Git | What is GitHub | Git Tutorial | GitHub Tutorial | Devops Tutori...
Deploying R for Production - SRUG
Experts Live Switzerland 2017 - Automatisierte Docker Release Pipeline mit VS...
CICD_1670665418.pdf
Jenkins vs GitLab CI
Building Slack's internal developer platform as a product.pdf
Better Operations into the Cloud
Continuos Integration and Delivery: from Zero to Hero with TeamCity, Docker a...
CI/CD with Jenkins and Docker - DevOps Meetup Day Thailand
Ad

More from Docker, Inc. (20)

PDF
Containerize Your Game Server for the Best Multiplayer Experience
PDF
How to Improve Your Image Builds Using Advance Docker Build
PDF
Build & Deploy Multi-Container Applications to AWS
PDF
Securing Your Containerized Applications with NGINX
PDF
How To Build and Run Node Apps with Docker and Compose
PDF
Hands-on Helm
PDF
Distributed Deep Learning with Docker at Salesforce
PDF
The First 10M Pulls: Building The Official Curl Image for Docker Hub
PDF
Monitoring in a Microservices World
PDF
COVID-19 in Italy: How Docker is Helping the Biggest Italian IT Company Conti...
PDF
Predicting Space Weather with Docker
PDF
Become a Docker Power User With Microsoft Visual Studio Code
PDF
How to Use Mirroring and Caching to Optimize your Container Registry
PDF
Monolithic to Microservices + Docker = SDLC on Steroids!
PDF
Kubernetes at Datadog Scale
PDF
Labels, Labels, Labels
PDF
Using Docker Hub at Scale to Support Micro Focus' Delivery and Deployment Model
PDF
Build & Deploy Multi-Container Applications to AWS
PDF
From Fortran on the Desktop to Kubernetes in the Cloud: A Windows Migration S...
PDF
Developing with Docker for the Arm Architecture
Containerize Your Game Server for the Best Multiplayer Experience
How to Improve Your Image Builds Using Advance Docker Build
Build & Deploy Multi-Container Applications to AWS
Securing Your Containerized Applications with NGINX
How To Build and Run Node Apps with Docker and Compose
Hands-on Helm
Distributed Deep Learning with Docker at Salesforce
The First 10M Pulls: Building The Official Curl Image for Docker Hub
Monitoring in a Microservices World
COVID-19 in Italy: How Docker is Helping the Biggest Italian IT Company Conti...
Predicting Space Weather with Docker
Become a Docker Power User With Microsoft Visual Studio Code
How to Use Mirroring and Caching to Optimize your Container Registry
Monolithic to Microservices + Docker = SDLC on Steroids!
Kubernetes at Datadog Scale
Labels, Labels, Labels
Using Docker Hub at Scale to Support Micro Focus' Delivery and Deployment Model
Build & Deploy Multi-Container Applications to AWS
From Fortran on the Desktop to Kubernetes in the Cloud: A Windows Migration S...
Developing with Docker for the Arm Architecture

Recently uploaded (20)

PDF
Ebook - The Future of AI A Comprehensive Guide.pdf
PDF
Uncertainty-aware contextual multi-armed bandits for recommendations in e-com...
PDF
Intravenous drug administration application for pediatric patients via augmen...
PPTX
Rise of the Digital Control Grid Zeee Media and Hope and Tivon FTWProject.com
PDF
【AI論文解説】高速・高品質な生成を実現するFlow Map Models(Part 1~3)
PDF
ment.tech-How to Develop an AI Agent Healthcare App like Sully AI (1).pdf
PDF
Examining Bias in AI Generated News Content.pdf
PDF
Slides World Game (s) Great Redesign Eco Economic Epochs.pdf
PPTX
Blending method and technology for hydrogen.pptx
PPTX
Presentation - Principles of Instructional Design.pptx
PPTX
From Curiosity to ROI — Cost-Benefit Analysis of Agentic Automation [3/6]
PDF
Optimizing bioinformatics applications: a novel approach with human protein d...
PDF
TicketRoot: Event Tech Solutions Deck 2025
PDF
FASHION-DRIVEN TEXTILES AS A CRYSTAL OF A NEW STREAM FOR STAKEHOLDER CAPITALI...
PDF
EGCB_Solar_Project_Presentation_and Finalcial Analysis.pdf
PDF
eBook Outline_ AI in Cybersecurity – The Future of Digital Defense.pdf
PPTX
Introduction-to-Artificial-Intelligence (1).pptx
PDF
The Basics of Artificial Intelligence - Understanding the Key Concepts and Te...
PDF
Addressing the challenges of harmonizing law and artificial intelligence tech...
PDF
State of AI in Business 2025 - MIT NANDA
Ebook - The Future of AI A Comprehensive Guide.pdf
Uncertainty-aware contextual multi-armed bandits for recommendations in e-com...
Intravenous drug administration application for pediatric patients via augmen...
Rise of the Digital Control Grid Zeee Media and Hope and Tivon FTWProject.com
【AI論文解説】高速・高品質な生成を実現するFlow Map Models(Part 1~3)
ment.tech-How to Develop an AI Agent Healthcare App like Sully AI (1).pdf
Examining Bias in AI Generated News Content.pdf
Slides World Game (s) Great Redesign Eco Economic Epochs.pdf
Blending method and technology for hydrogen.pptx
Presentation - Principles of Instructional Design.pptx
From Curiosity to ROI — Cost-Benefit Analysis of Agentic Automation [3/6]
Optimizing bioinformatics applications: a novel approach with human protein d...
TicketRoot: Event Tech Solutions Deck 2025
FASHION-DRIVEN TEXTILES AS A CRYSTAL OF A NEW STREAM FOR STAKEHOLDER CAPITALI...
EGCB_Solar_Project_Presentation_and Finalcial Analysis.pdf
eBook Outline_ AI in Cybersecurity – The Future of Digital Defense.pdf
Introduction-to-Artificial-Intelligence (1).pptx
The Basics of Artificial Intelligence - Understanding the Key Concepts and Te...
Addressing the challenges of harmonizing law and artificial intelligence tech...
State of AI in Business 2025 - MIT NANDA

Building a Secure Supply Chain with Docker