notation
cuetorials.com
Our great sponsors
notation | cuetorials.com | |
---|---|---|
7 | 27 | |
289 | 113 | |
6.6% | -0.9% | |
8.9 | 4.1 | |
6 days ago | 29 days ago | |
Go | CUE | |
Apache License 2.0 | BSD 3-clause "New" or "Revised" License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
notation
-
Securing CI/CD Images with Cosign and OPA
Notary v2: The evolution to Notary v2 brought improvements in signature portability and integration with third-party key management solutions. However, it does not provide a certificate authority, leaving public key discovery for open-source image verification as an unresolved issue.
-
Automating Kubernetes Deployments with FluxCD for Patched and Signed Container Images
Notation
-
Level-up Container Security: 4 Open-Source Tools for Secure Software Supply Chain
Notation is another command-line too that lets you digitally sign artifacts. And those signatures essentaily become the stamps of approval for the different things in your software supply chain. For example, container images.
- notaryproject/notation: Notation is a project to add signatures as standard items in the registry ecosystem, and to build a set of simple tooling for signing and verifying these signatures. Based on Notary V2 standard.
-
Getting Started with Notary
Notary is the CNCF project name and is often referenced when referring to the process of signing digital artifacts, but Notation is the command line tool that does the heavy lifting. Run the following commands to install Notation.
- Dagger: a new way to build CI/CD pipelines
-
Making the Internet more secure one signed container at a time
It should be interoperable, that's the goal. I proposed some idea for nv2 here: https://github.com/notaryproject/nv2/issues/39 and here: https://github.com/notaryproject/nv2/issues/40 too.
cuetorials.com
-
HCL: Toolkit for Structured Configuration Languages
I have a website I maintain, many people tell me it has helped them
https://cuetorials.com
-
Ask HN: Comment here about whatever you're passionate about at the moment
CUE(lang), because devops & yaml engineering has gotten out of hand
I maintain https://cuetorials.com and am heading up the CUE sig-infra group for the time being
- That's a Lot of YAML
-
Ask HN: Who needs vendors, and vendors, who needs customers?
If you need help with CUE(lang), we maintain https://cuetorials.com and have experience helping others adopt it at their companies
email is in my HN profile, same handle on GitHub and X
- Learn you some CUE for a great good
-
Ask HN: Which Python or Rust-based static site generators to use as of 2023?
If you are more focused on the devops part, and not implementing a static site generator, then go with Python. For our static sites we use Hugo + GH Actions + Kubernetes (since we have a cluster anyway). There is not really any code involved here (example: https://github.com/hofstadter-io/cuetorials.com)
I'm personally interested to try https://docs.dagger.io/sdk/python/ for something. I used the CUE sdk, but it is effectively deprecated at this point. I use a mix of base, make, python, and CUE fro most devops / devex stuff now. Dagger makes it so local & CI stuff runs the same.
- Cue Wins
- Ask HN: Do you have something you continually work on for years?
-
Ask HN: How to find the right tech angel investor for new programming platform?
yup, I'm betting the proverbial ranch on CUE :]
I also maintain https://cuetorials.com
-
hof: The High Code Framework (low-code for devs), a flexible data modeling & code generation system
I also maintain https://cuetorials.com, bet the farm on CUE or something like that :]
What are some alternatives?
cosign - Code signing and transparency for containers and binaries
vector - A high-performance observability data pipeline.
net-monitor - The sample net-monitor software, used as samples in Notary v2 (https://github.com/notaryproject/notaryproject)
juicefs - JuiceFS is a distributed POSIX file system built on top of Redis and S3.
ratify - Artifact Ratification Framework
cue - The home of the CUE language! Validate and define text-based and dynamic configuration
grafeas - Artifact Metadata API
cue - CUE has moved to https://github.com/cue-lang/cue
secure-supply-chain-on-aks - Learn how to use open-source tools to secure your container deployments on Azure Kubernetes Service.
hof - Framework that joins data models, schemas, code generation, and a task engine. Language and technology agnostic.
distribution - distribution with reference types
VuePress - 📝 Minimalistic Vue-powered static site generator