When Federal people ask to secure a DevOps app creation and delivery process, what do they mean? Chris Willis joins Coté in this episode to answer that question with a #vmwaretanzu customer example: the Tanzu Build Service, buildpacks, Tanzu Application Service (Pivotal Cloud Foundry), and other components. He covers FIPS encryption requirements, STIGs, working with the authorizing official, and the overall practices and culture-think for securing build pipelines.
Related content in this Stream

What is VMware Tanzu? I get asked this question a lot and, you know, I try to explain it. If you want a really good explanation, you should check out a new book on the topic, DevSecOps in Practice...

With VMware Tanzu Application Platform 1.4, available now, teams can cut down on developer toil and enhance operations and security, improving their overall DevSecOps experiences and outcomes.

VMware announces new capabilities in Tanzu Application Platform that enhance developer and application operator experiences for any Kubernetes environment, increase supply chain security, and more!

VMware is innovatively leveraging Bitnami's capabilities to address the security and tooling challenges faced by enterprises in their multi-cloud and app modernization initiatives.

Learn how enterprises and ISVs can use VMware Image Builder to securely automate the processes of packaging, verifying, and publishing applications and save their DevSecOps team’s valuable time.

Tanzu Application Platform version 1.2 focuses on readiness of more environments, from cloud-first to highly regulated with an enhanced DevSecOps experience.

The main difference between DevOps and DevSecOps is security automation, but the nuances and benefits are just as important. Learn more with VMware Tanzu.

Whether you’re new to or experienced with Cartographer—an open source project designed to build and manage modern, secure software supply chains—discover how it helps boost DevSecOps productivity.

Kpack, a Kubernetes-native container build platform and a powerful tool for DevSecOps teams, is now included in VMware Tanzu Community Edition.
11:07Recently, security has emerged as one of the most important issues in DevOps for modern applications with open source tools being heavily in use. With this, we will look into DevSecOps featuring incre
6:10This video demonstrates how you can use the VMware Tanzu Application Platform to help accelerate your organization's DevSecOps culture. We demonstrate how Tanzu Application Platform can use an outer l
5:57This video demonstrates how you can use the VMware Tanzu Application Platform to help accelerate your DevSecOps culture. In it, we show how the Tanzu Application Platform can use an outer loop supply

This library of validated, production-ready container images will soon support virtual machine images, making it even easier for teams to implement DevSecOps practices.
58:07Security as Code (SaC) is the methodology of codifying security tests, scans, and policies. Security is implemented directly into the CI/CD pipeline to automatically and continuously detect security v









