首页> 外文会议>Annual Computing and Communication Workshop and Conference >A Kubernetes CI/CD Pipeline with Asylo as a Trusted Execution Environment Abstraction Framework
【24h】

A Kubernetes CI/CD Pipeline with Asylo as a Trusted Execution Environment Abstraction Framework

机译:一个Kubernetes CI / CD管道,具有asylo作为可信执行环境抽象框架

获取原文

摘要

Modern commercial software development organizations frequently prescribe to a development and deployment pattern for releases known as continuous integration / continuous deployment (CI/CD). Kubernetes, a cluster-based distributed application platform, is often used to implement this pattern. While the abstract concept is fairly well understood, CI/CD implementations vary widely. Resources are scattered across on-premise and cloud-based services, and systems may not be fully automated. Additionally, while a development pipeline may aim to ensure the security of the finished artifact, said artifact may not be protected from outside observers or cloud providers during execution. This paper describes a complete CI/CD pipeline running on Kubernetes that addresses four gaps in existing implementations. First, the pipeline supports strong separation-of-duties, partitioning development, security, and operations (i.e., DevSecOps) roles. Second, automation reduces the need for a human interface. Third, resources are scoped to a Kubernetes cluster for portability across environments (e.g., public cloud providers). Fourth, deployment artifacts are secured with Asylo, a development framework for trusted execution environments (TEEs).
机译:现代商业软件开发组织经常规定称为连续集成/连续部署(CI / CD)的版本的开发和部署模式。基于群集的分布式应用程序平台Kubernetes通常用于实现此模式。虽然抽象概念很好地理解,但CI / CD实现差异很大。资源分散在内部部署和基于云的服务,系统可能无法完全自动化。另外,虽然开发流水线可以旨在确保成品伪像的安全性,但是在执行期间可能不会免于外部观察者或云提供商的保护。本文介绍了在Kubernetes上运行的完整CI / CD管道,该方法在现有实现中解决了四个间隙。首先,管道支持强大的职责分离,分区开发,安全性和操作(即,Devsecops)角色。其次,自动化减少了对人类界面的需求。第三,资源被视为Kubernetes集群,以跨环境的可移植性(例如,公共云提供商)。第四,部署工件用asylo保护,是可信执行环境的开发框架(T恤)。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号