Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Presentation] Presenting external-secrets-operator project #1428

Closed
3 of 4 tasks
Skarlso opened this issue Dec 13, 2024 · 13 comments
Closed
3 of 4 tasks

[Presentation] Presenting external-secrets-operator project #1428

Skarlso opened this issue Dec 13, 2024 · 13 comments
Assignees
Labels
usecase-presentation Label for usecase related presentations

Comments

@Skarlso
Copy link
Contributor

Skarlso commented Dec 13, 2024

Title: Presenting external-secrets-operator

Speakers: Gergely Brautigam (@Skarlso)

Description: Presenting External Secrets, showing up it's features, talk about pushing/pulling/generating and rotating secrets.

Time: 10-20 minutes based on how much detail is provided.

Availability: EMEA TZ, Suggestion: 18th of December.

TO DO

  • TAG Representative @mrcdb
  • Schedule date 15th January 2025
  • By opening this issue, I, (Insert Github Handle/Name) acknowledge that the presentation topic and speaker will follow the presentation guidelines
  • If this is a presentation for a project moving levels, the TAG Representative should complete the Moving Levels Recommendation
@Skarlso Skarlso added triage-required Requires triage usecase-presentation Label for usecase related presentations labels Dec 13, 2024
@gusfcarvalho
Copy link

It there a way to know when this is going to be scheduled? 😄

@mnm678
Copy link
Collaborator

mnm678 commented Dec 23, 2024

The next EMEA meeting will be on Jan 15. Are you available then or on Jan 29? cc @mrcdb

@mrcdb
Copy link
Member

mrcdb commented Dec 23, 2024

hey @Skarlso , as @mnm678 has mentioned the next EMEA meetings will be on January 15 and 29 at 1PM UK, please let us know what works best for you and we can add it to the meeting schedule.

@Skarlso
Copy link
Contributor Author

Skarlso commented Dec 23, 2024

Hello! :)

15th of January works nicely for me 1PM UK is 2PM for me which is perfect. :)

Thank you! 🎉 🚀

@mrcdb
Copy link
Member

mrcdb commented Dec 23, 2024

Added to the meeting schedule for the 15th of January.

You'll find the meeting information here 👍🏻

EDIT: Please find here the presentation guidelines: https://github.com/cncf/tag-security/blob/main/CONTRIBUTING.md#present-to-the-tag

@mrcdb mrcdb self-assigned this Dec 23, 2024
@mrcdb mrcdb removed the triage-required Requires triage label Dec 23, 2024
@Skarlso
Copy link
Contributor Author

Skarlso commented Dec 23, 2024

Thank you! Will do! :)

@eddie-knight
Copy link
Collaborator

eddie-knight commented Jan 15, 2025

(edit: moving this WIP notes to a finalized comment at the bottom, following review by the TAG tech leads)

@Skarlso
Copy link
Contributor Author

Skarlso commented Jan 15, 2025

@eddie-knight I didn't know correctly, we don't have a dedicated security person to advice us. All maintainers review security advisory items. Does that count? :D

@eddie-knight
Copy link
Collaborator

@Skarlso — Capturing the name of a security champion is mostly for our TAG's future reference. The champion isn't an official title or role or even expertise, but would be the go-to person for discussions about project security.

@gusfcarvalho
Copy link

gusfcarvalho commented Jan 15, 2025

Even though I do not find myself an expert, I do enjoy the security theme :)

I volunteer for this role @eddie-knight @Skarlso 😄

edit: I'm also one of external-secrets maintainers

@Skarlso
Copy link
Contributor Author

Skarlso commented Jan 15, 2025

Ah gotcha. Nice, Gustavo. :) I actually was thinking about you when talking on the meeting earlier but didn't want to volunteer you hahahaha.

@eddie-knight
Copy link
Collaborator

TAG recommendation to TOC

Project Overview

Security Champion

Gustavo Fernandes de Carvalho @gusfcarvalho

Ecosystem Adoption

The External Secrets Operator (ESO) project has wide adoption by different large organizations.

The project repository shows 4.6K stars with 433 contributors, and 2025 users are present on the CNCF Slack #external-secrets channel.

Past TOC Reviews

The project has undergone a previous TOC review as part of its sandbox application, and promptly addressed comments re: project security (i.e. start on a CII best practices badge, adoption of a license scanning tool).

Security Reviews

TAG Security Assessments

The project has completed a self-assessment with the TAG as part of the Security Pals initiative (PR) , with further updates to the assessment by the project maintainers (PR). No security findings or immediate recommendations have been raised by reviewers during the self-assessment process.

Security Audit

No formal external security audit has been completed yet, although the project has produced a threat model. An additional threat model based on the STRIDE framework is also available.

Best Practices

Metrics

The project follow a number of security best practices: CLOmonitor, OpenSSF Best Practices, OpenSSF Scorecard.

Metrics are reported as follows with relevant links:

  • CLOmonitor 96
  • OpenSSF Best Practices Passing
  • OpenSSF Scorecard 7.4

Static Analysis

The project leverages Sonarcloud SAST scanning and FOSSA license scanning.

Sub-project Considerations

The ESO project does not have sub-projects.

TAG Recommendation to the TOC

The External Secrets Operator project has seen wide adoption and shows attention to security best practices and proactive threat modeling. Based on these observations, the project appears to fully meet the expectations of a project at the incubating stage.

@Skarlso
Copy link
Contributor Author

Skarlso commented Jan 22, 2025

Thank you, @eddie-knight

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
usecase-presentation Label for usecase related presentations
Projects
None yet
Development

No branches or pull requests

5 participants