Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Suggestion] Requesting a security representative for the Kubernetes Data Protection WG #1034

Open
xing-yang opened this issue Feb 8, 2023 · 15 comments
Labels
suggestion New suggestion for the CNCF sig-security group that don't fall into an existing category

Comments

@xing-yang
Copy link

Description: What's your idea?

In the charter of the Kubernetes Data Protection WG, we have a note that we'll consult CNCF TAG Security for security related issues:
https://github.com/kubernetes/community/blob/master/wg-data-protection/charter.md
However, we don't have a security representative in the WG.
I'm opening this issue to see if there's anyone interested in helping out.

Impact: Describe your hopes for how this would reduce risk for the cloud native ecosystem. Who will this help? How will it help them?

This security representative will bring in security awareness to the K8s DP WG.

Scope: How much effort will this take? ok to provide a range of options if or "not yet determined"

Not yet determined.

Additional info:

  • Reference to supporting material
  • Links to related site
  • Feel free to delete this section if you don't have more info
@xing-yang xing-yang added suggestion New suggestion for the CNCF sig-security group that don't fall into an existing category triage-required Requires triage labels Feb 8, 2023
@lumjjb
Copy link
Collaborator

lumjjb commented Feb 8, 2023

Hi @xing-yang , would you or someone from the WG be able to come to talk a bit more about this during our weekly TAG meetings? It can definitely help with figuring out the scoping!

@xing-yang
Copy link
Author

Hi @lumjjb, sure! I can join one of your weekly meeting to talk about this. I'll see if anyone else from our DP WG is interested as well. It looks like your next meeting (U.S. time) is on 2/22 at 10am ET? Does that work or would you suggest a different time?

@lumjjb
Copy link
Collaborator

lumjjb commented Feb 22, 2023

Hi @xing-yang , would you be able to do the next meeting on the 8th of March at 1pm ET? Sorry missed this previous message.

@jkjell
Copy link
Collaborator

jkjell commented Mar 22, 2023

In a past life, I worked on data protection. 😅 I'm interested in helping out if I can, depending on what sort of help you're looking for.

@xing-yang
Copy link
Author

Hi @lumjjb and @jkjell, sorry that I missed these messages! We are working on a design to support Changed Block Tracking. We'd like someone with security background to weigh in. Let me ping you after KubeCon. Thanks!

@stale
Copy link

stale bot commented Jun 18, 2023

This issue has been automatically marked as inactive because it has not had recent activity.

@stale stale bot added the inactive No activity on issue/PR label Jun 18, 2023
@anvega
Copy link
Collaborator

anvega commented Jun 21, 2023

Designated @lumjjb and @jkjell. Hopefully you've been able to connect and progress the collaboration directly. Feel free to reopen the issue if you seek out additional reps.

@anvega anvega closed this as completed Jun 21, 2023
@xing-yang
Copy link
Author

Thank you, @anvega @lumjjb @jkjell !

@xing-yang
Copy link
Author

We have a WIP KEP that needs to be updated based on the new design. Will ping you folks when that's ready for review.

@anvega
Copy link
Collaborator

anvega commented Jun 21, 2023

Thanks @xing-yang

@xing-yang
Copy link
Author

@lumjjb and @jkjell, this KEP is ready for review now. Would appreciate if you could take a look. Thanks!

@anvega anvega reopened this Jul 14, 2023
@stale stale bot removed the inactive No activity on issue/PR label Jul 14, 2023
@PushkarJ
Copy link
Collaborator

PushkarJ commented Jul 14, 2023

@xing-yang do you mind sharing / if I share this KEP in SIG security slack channel and then you can add more context as needed ?

This way we may get more eyes on it outside and within TAG security folks

@anvega
Copy link
Collaborator

anvega commented Aug 1, 2023

@lumjjb @jkjell @PushkarJ Did the review of the KEP take place?

@PushkarJ
Copy link
Collaborator

PushkarJ commented Aug 1, 2023

@anvega Not yet as far as I can tell
@xing-yang I will go ahead and share it, if you don't have any concerns

@xing-yang
Copy link
Author

Hi @PushkarJ , here's the KEP. Please go ahead and share it. Thanks!

@PushkarJ PushkarJ removed the triage-required Requires triage label Aug 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
suggestion New suggestion for the CNCF sig-security group that don't fall into an existing category
Projects
None yet
Development

No branches or pull requests

5 participants