Loading…
May 10-12, 2023
Vancouver, British Columbia, Canada + Virtual
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2023 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Pacific Daylight Time (UTC/GMT -8). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

Wednesday, May 10 • 4:00pm - 4:40pm
Securing Your Infrastructure as Code Pipeline - Jesse Sanford, Autodesk

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
The meteoric rise of platform engineering has led to a proliferation of self-service and on demand infrastructure as code solutions. The benefits to product team productivity through reduced cognitive load have been widely published. Yet lesser known, but no less important, are the security and compliance benefits achieved through a uniform platform interface. This talk will show that by producing IaC with a strong separation of concerns between platform engineers and their product counterparts, common fundamentals and non-negotiables can be baked in. These guard rails can be enforced through the use of static analysis tools and RBAC allowing for walled garden ecosystems of known good IaC. In this talk, Jesse will cover the capabilities Autodesk is building into their cloud deployment platform, using tools such as Open Policy Agent, in-toto, Sigstore’s suite, Crossplane and more. Jesse will detail how Autodesk is structuring their CI and CD systems to produce IaC pipelines that are inspectable, verifiable and ultimately trustable. From cryptographically verifiable IaC package signing to static analysis of IaC plans to deploy time policy enforcement, these open source tools and patterns can be used by anyone with the thirst to create a platform that increases velocity and safety!

Speakers
avatar for Jesse Sanford

Jesse Sanford

Software Architect, Autodesk
Jesse is a lifelong software engineer focused on site reliability and Infosec. Currently architecting the juncture of platform engineering and security/compliance for Autodesk's Developer Enablement team. He regularly contributes to open source and frequently speaks about his work... Read More →


Wednesday May 10, 2023 4:00pm - 4:40pm PDT
110 (Level 1)