Your artifacts may be signed, but do you know who actually signed them? Many teams use Sigstore for keyless signing and Keycloak for identity. But when these systems aren't connected, it's hard to prove that every signature truly belongs to the right person or service. That weakens trust in the software supply chain. At KubeCon Japan, Oshi Gupta will show how to integrate Keycloak with Sigstore's keyless signing flow, so every signed artifact is cryptographically tied to a verified identity under your own control. The session also covers Fulcio configuration, identity claims, and real-world challenges you'll face in production. If you're building secure software delivery pipelines, don't miss this session. #KubeCon #KubeConJapan #Sigstore #Keycloak #SoftwareSupplyChain #DevSecOps #CloudNative
Integrate Keycloak with Sigstore for Secure Software Delivery
More Relevant Posts
-
4 ways to charge your customers using BizNiz Optimizer: - Create a payment link for the order. Send it to the customer. Customer pays online and the payment gets registered in the app. - Send a request to a physical terminal. Customer pays with card on the terminal and the payment gets registered in the app. - If the customer has previously made a card purchase on your payment terminal (and you have customer consent), you can use card-on-file to charge for an order. - ...and there is of course also always the option to manually register a payment in the app. #BizNizOptimizer #AMPPaymentSystems
Bizniz Optimizer, now fully integrated with #AMPPaymentSystems. Just click the order amount and: 1. Create a payment link for online payment or 2. Connect to your physical terminal for in-store payment. or 3. Use card-on-file to charge the customer for the order. Once payment is done it's immediately registered in Bizniz Optimizer.
To view or add a comment, sign in
-
-
🔐 One Hostname, Every Tenant’s IdP In our latest technical blog, we share why we moved from Keycloak to Zitadel and how we approached multi-tenant identity without creating unnecessary complexity around domains and authentication. A small look into the architecture decisions, trade-offs, and lessons behind building a cleaner identity layer for a multi-tenant platform. ⚙️ 👉 Read the full blog: https://lnkd.in/gAXXEhZm #Zitadel #Keycloak #IdentityManagement #IAM #Authentication #Authorization #MultiTenant #MultiTenancy #SoftwareArchitecture #SystemDesign #PlatformEngineering #CloudNative #DevOps #Kubernetes #SaaS #SaaSArchitecture #BackendEngineering #SoftwareEngineering #Engineering #TechBlog #BuildInPublic #Tesserix
To view or add a comment, sign in
-
After working on Smartlog for many years and listening to our customers feedback, I am excited to say we are bringing our new module ‘Calendar View’ to Smartlog 6! 🥳 This highly requested feature will bring all your upcoming tasks and deadlines into one screen, improving visibility whether that be for checks, training or document reviews, making it perfect for planning ahead, with full daily breakdowns to make sure you don’t miss a thing. On the face of it, it might look like a simple change, but we’re hoping it will make a huge difference to our clients’ processes and daily experience, which is only made possible by the new platform upgrades. ⚙️ #Development #Smartlog6
To view or add a comment, sign in
-
-
Today we just released v2.0 of zkao, our automated tool to find bugs. The average scan takes 9h to run, and costs a fraction of the price of an audit. Our clients have used it to find numerous critical bugs in their codebase. We built the tool we wanted for ourselves, gave our clients access, and now we're making it public. It's a no brainer, if you have code running in production, don't wait, just run a zkao scan. https://www.zkao.io
To view or add a comment, sign in
-
crumb's on pypi. the problem it solves.. when an agent calls a tool, the log says the agent did it. it doesn't say which human authorized it. fine until something goes wrong and you need to know who. crumb writes a signed record per tool call and anchors the chain in sigstore's public transparency log. pip install crumb-attest, then point crumb verify at my live demo ledger. it checks the chain and the signatures, pulls the rekor entry live, compares. green in about a second. then trip the rollback on the demo. it rewrites a crumb, the ledger still looks internally consistent, and the anchor catches it anyway. crumb.alexlaguardia.dev
To view or add a comment, sign in
-
Payments are distributed workflows, not single button clicks. The interface may say “processing” while a provider completes the transaction later. Events can be retried, requests can time out, and refunds create another lifecycle. Without explicit states and idempotent handling, one ambiguous outcome can become duplicate fulfilment or inconsistent records. At Softotic, we design payment architecture around verified events, deliberate state transitions, duplicate protection, and reconciliation—so the product remains understandable when the happy path ends. If money moves through your software, every possible state deserves a design decision. www.softotic.com #PaymentArchitecture #SoftwareEngineering #BackendDevelopment #ProductReliability #Softotic
To view or add a comment, sign in
-
-
Data portability is more than adding a download button. A dependable export needs clear scope, stable field definitions, preserved relationships, consistent timestamps, safe generation, and formats that remain useful outside the original product. Large exports also need reliable background processing, access controls, expiry rules, and an understandable delivery experience. At Softotic, we design data portability across the product journey and the underlying architecture—so users receive complete records without weakening security or operational reliability. Products earn trust when data ownership remains practical, not merely promised. www.softotic.com #DataPortability #SoftwareArchitecture #ProductEngineering #DigitalTrust #Softotic
To view or add a comment, sign in
-
-
Reliable mobile products are designed for imperfect networks. Offline-first architecture is more than caching a few screens. It requires clear ownership of local data, predictable conflict handling, safe synchronization, and recovery states users can understand. At Softotic, we engineer mobile experiences that protect essential journeys through connection loss and reconcile changes carefully when the network returns. If connectivity is a real constraint for your users, it should be part of the product architecture from day one. www.softotic.com #MobileEngineering #OfflineFirst #SoftwareArchitecture #ProductDevelopment #Softotic
To view or add a comment, sign in
-
-
The infrastructure we depend on should be open, accessible, and built to serve the whole of humanity. At our next OSA Community event, we’ll take a dive deep on Artifact Keeper, an MIT-licensed artifact management platform, that makes essential software supply chain security capabilities accessible to all. Built largely by one engineer in just 6 months, it’s also an interesting case study in what’s now possible with open source and AI-assisted development. Save your spot: https://lnkd.in/g8BPJizS #OpenSource #SupplyChainSecurity #DevSecOps #ArtifactManagement #OpenSourceArchitect
To view or add a comment, sign in
-
-
I saw this demonstrated live in front of a group last week. If you’re interested in an artifact data solution that’s open source, I know a guy named Brandon Geraci who can talk to you about Artifact Keeper!
The infrastructure we depend on should be open, accessible, and built to serve the whole of humanity. At our next OSA Community event, we’ll take a dive deep on Artifact Keeper, an MIT-licensed artifact management platform, that makes essential software supply chain security capabilities accessible to all. Built largely by one engineer in just 6 months, it’s also an interesting case study in what’s now possible with open source and AI-assisted development. Save your spot: https://lnkd.in/g8BPJizS #OpenSource #SupplyChainSecurity #DevSecOps #ArtifactManagement #OpenSourceArchitect
To view or add a comment, sign in
-
More from this author
Explore content categories
- Career
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Hospitality & Tourism
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development
Excited for Japan to get insights from Oshi Gupta. She's a wealth of knowledge!