Securing the Software Supply Chain with SLSA/FRSCA gives working technology professionals a comprehensive, hands-on introduction to the SLSA framework and its FRSCA reference implementation. The course runs across three intensive days. Attendees leave with a clear understanding of SLSA and its principal features and use cases.
Day one lays the SLSA foundation with an overview of the framework’s assurance levels. Students also look at the supply chain threats those levels defend against, and get hands-on work with provenance and Verification Summary Attestation. The day closes with a survey of related standards and tooling that complement the framework.
Day two moves into FRSCA, the reference implementation of SLSA, starting with deploying it on Kubernetes. Students then build secure pipelines with Tekton Pipelines and Chains and sign and verify artifacts using Sigstore. They also apply workload identity to pipeline components with SPIFFE and SPIRE.
Day three completes the build, managing pipeline secrets with Vault and packaging and deploying FRSCA components with Helm. Students also apply CUE for supply chain policy and configuration. A closing summary ties the levels, threats, and tools back together before next steps. Students gain hands-on experience with SLSA tools and the FRSCA reference implementation through a series of labs. These labs demonstrate all of the platform’s key features. By the end of the course, each student has built a complete software artifact build pipeline, implementing SLSA through the FRSCA model.
Who Should Attend
IT and QA Staff, Developers, Technical Managers, SRE/DevOps/DevSecOps/PlatformOps and Build personnel
What Attendees Will Learn
Upon completing Securing the Software Supply Chain with SLSA/FRSCA, attendees will be able to:
- Explain SLSA framework levels and supply chain threat concepts
- Apply provenance and Verification Summary Attestation practices
- Deploy FRSCA on Kubernetes as a SLSA reference implementation
- Build secure pipelines using Tekton Pipelines and Chains
- Sign and verify artifacts using Sigstore
- Apply workload identity using SPIFFE/SPIRE
- Manage secrets using Vault within a supply chain pipeline
- Package and deploy FRSCA components using Helm
- Apply CUE for supply chain policy and configuration
Prerequisites
Students should have taken the RX-M “Kubernetes Foundation” course or have equivalent knowledge including some experience with Linux and Linux containers.