Note: SIG-Security was rebranded from SAFE working group. The below roadmap includes SAFE WG and SIG-Security in its timeline.
#2 Discover | #3 Describe | #4 Identify | |
---|---|---|---|
Artifacts | Personas Use Cases Categories |
Standards Common Definitions Block Architecture |
Catalog Projects Fill in Boxes Identify Gaps |
Topics | Presentations SIG members & guests |
Standards in Practice Real World Systems Architecture |
Platforms & Products Tools & Libraries |
- Charter the SAFE Working Group. Draft vision, process and initial members (done, see below)
- Discover (in progress)
- Explore the problem space of the working group
- Investigating what is happening in the community today with respect to security for cloud native applications and infrastructure
- Presentations from members & guests
- Describe personas & use cases
- Draft a picture or set of categories that will serve as a starting point for an evaluation framework
- Solicit real world use cases and practices (and compensating controls) for projects
- Describe the landscape
- Define the terminology used in the output documents, and in the community
- Describe the current state (landscape) of cloud native security, which might include:
- existing standards
- existing open source, and proprietary, solutions
- common patterns in use today for system that works for cloud-native apps. For example:
- Extract end-to-end view of secure access, and
- Common layering or a block architecture
- Identify existing security components in CNCF and projects in the CNCF landscape and catalog
- Identify gaps and make recommendations to the community and TOC
- Continually monitor the viability of the existing projects and update the landscape document
- Document and disseminate best practices (provide training?)
Milestone | Date | Action |
---|---|---|
Updated Charter and Governance ratified by CNCF TOC | 7 May 2019 | New repo |
Moved SAFE WG to CNCF | 15 Apr 2019 | Repo rename |
CNCF WG proposal | 21 Aug 2018 | CNCF SIG-Security charter and roles |
Policy WG merged | 10 Aug 2018 | Merging policy WG |
Initial Commit for SAFE repo | 13 Mar 2018 | First commit |
Informal discussions at Kubecon Austin | Dec 2017 | Meeting with CNCF community and gathering feedback |