返回排行榜

cncf/tag-security

HTMLtag-security.cncf.io

🔐CNCF Security Technical Advisory Group -- secure access, policy control, privacy, auditing, explainability and more!

cloud-nativesecurityaccess-controlsafetysecure-accesscncfassessment
Star 增长趋势
Star
2.3k
Forks
578
周增长
Issues
13
1k2k
2018年3月2020年12月2023年10月2026年7月
README

Security Technical Advisory Group

Cloud Native Security Logo

About Us

The CNCF Security Technical Advisory Group facilitates collaboration to exchange and produce knowledge and resources for building security in the cloud native ecosystem.

Cloud Native involves building, deploying, and operating modern applications in cloud computing environments, typically using open source. This complex ecosystem presents a technology risk landscape that demands rethinking application and information security through the lens of developer experience.

We aim to significantly reduce the probability and impact of attacks, breaches, and compromises. By empowering developers and operators to understand and manage the security posture of their systems, we strive to fulfill the promise of enhanced productivity and operational efficiency.

Key Focus Areas

  • System Security Architectures: Frameworks to protect resources and data.
  • Common Lexicon, Templates & Libraries: Tools for developers to create secure apps.
  • Heuristics and Models: Approaches for reasoning about system security.

Publications

Below is a list of publications by TAG Security. For a comprehensive collection of our works in various formats, please visit the publications directory.

Publication Latest Release
Catalog of Supply Chain Compromises November 2019 - Present
Software Supply Chain Best Practices March, 2025
Open and Secure - A Manual for Practicing Threat Modeling to Assess and Fortify Open Source Security November, 2023
Handling Build-time Dependency Vulnerabilities June, 2022
Secure Software Factory: A Reference Architecture to Securing the Software Supply Chain May, 2022
Cloud Native Security Controls Catalog May, 2022
Cloud Native Security Whitepaper May, 2022
Secure Defaults February, 2022
Cloud Native Security Lexicon August, 2021
Evaluating your Supply Chain Security May, 2021
Formal Verification for Policy Configurations August, 2019

Governance

Refer to the Security TAG charter for our governance process.

Communications

Join our open discussions and share news:

Meeting Information

  • Americas: Weekly on Wednesdays at 10 am (UTC-7). Zoom link,
  • APAC: Bi-weekly on Thursday at 11 am (UTC+9). Zoom link.

Check your local timezone here. Meetings are listed on the CNCF calendar (filter by TAG Security and Compliance!)

To add a topic to the agenda, review our process.

New members

If you are new to the group, we encourage you to check out our contributing guidelines.

Explore groups affiliated with or relevant to Security TAG here

Leadership

Details about the TAG Chairs, Tech Leads, and TOC Liaisons can be found on the CNCF Technical Advisory Groups (TAGs) information page

TAG Emeritus Leaders

Thank you to all the tag emeritus leaders for your contributions to the success of this community.

Working Groups

The TAG's working groups focus on specific areas and organize most community activities, including weekly meetings. These groups facilitate discussions, engagement, and publications with key stakeholders, operating differently based on their needs. Each group, led by a responsible leader, reaches consensus on issues and manages logistics. All materials, such as reports, white papers, documents, and reference architectures, are in the repository's /community directory.

Project Leads STAG Rep
Automated Governance Brandt Keller Matthew Flannery
Catalog of Supply Chain Compromises Santiago Arias Torres Marina Moore
Commons Eddie Knight Marco De Benedictis
Compliance Anca Sailer, Robert Ficcaglia Brandt Keller
Security Assessments Justin Cappos Eddie Knight
Software Supply Chain Michael Lieberman Marina Moore

Additional information

CNCF Security TAG assessments

For CNCF project proposal process create a new security assessment issue with a self-assessment.

相关仓库
ClickHouse/ClickHouse

ClickHouse® is a real-time analytics database management system

C++Apache License 2.0dbmsolap
clickhouse.com
48.8k8.7k
milvus-io/milvus

Milvus is a high-performance, cloud-native vector database built for scalable vector ANN search

GoGo ModulesApache License 2.0annsnearest-neighbor-search
milvus.io
45.3k4.1k
Kong/kong

🦍 The API and AI Gateway

LuaApache License 2.0api-gatewaymicroservices
konghq.com/install/
43.8k5.2k
pingcap/tidb

TiDB is built for agentic workloads that grow unpredictably, with ACID guarantees and native support for transactions, analytics, and vector search. No data silos. No noisy neighbors. No infrastructure ceiling.

GoGo ModulesApache License 2.0distributed-databasedistributed-transactions
tidb.io
40.3k6.2k
zeromicro/go-zero

A cloud-native Go microservices framework with cli tool for productivity.

GoGo ModulesMIT Licensegolangmicroservice
go-zero.dev
33.2k4.3k
rustfs/rustfs

🚀2.3x faster than MinIO for 4KB object payloads. RustFS is an open-source, S3-compatible high-performance object storage system supporting migration and coexistence with other S3-compatible platforms such as MinIO and Ceph.

Rustcrates.ioApache License 2.0bigdatacloud-native
rustfs.com/download/
30.1k1.3k
alibaba/spring-cloud-alibaba

Spring Cloud Alibaba provides a one-stop solution for application development for the distributed solutions of Alibaba middleware.

JavaMavenApache License 2.0spring-cloudjava
sca.aliyun.com
29.1k8.5k
goharbor/harbor

An open source trusted cloud native registry project that stores, signs, and scans content.

GoGo ModulesApache License 2.0cncfcontainer
goharbor.io
29k5.3k
go-kratos/kratos

Your ultimate Go microservices framework for the cloud-native era.

GoGo ModulesMIT Licensegolangframework
go-kratos.dev
25.8k4.2k
taosdata/TDengine

High-performance, scalable time-series database designed for Industrial IoT (IIoT) scenarios

CGNU Affero General Public License v3.0iotbigdata
tdengine.com
25k5k
lensapp/lens

Lens - The way the world runs Kubernetes

MIT Licensekuberneteskubernetes-ui
lenshq.io
23.2k1.5k
alibaba/Sentinel

A powerful flow control component enabling reliability, resilience and monitoring for microservices. (面向云原生微服务的高可用流控防护组件)

JavaMavenApache License 2.0alibabajava
sentinelguard.io
23.1k8.1k