The practice of Cloud-Native DevSecOps has changed how companies deliver their software through automation, rapid iterations, and continuous deployments. DevSecOps offers greater agility and scalable options, however it creates significant challenges to securing the software supply chain through limitations in visibility, implicit trust that the pipeline being used is secure, and the challenge to establish consistently enforced security controls in dynamic environments. As supply-chain attacks are increasing due to the gap created by these operational challenges frequently using zero day vulnerabilities, compromised dependencies and AI driven evasion techniques, it is becoming clear that there is an urgent need to transition from conceptual security models into operationally enforceable solutions. This paper will explore the ways that the software supply chain can be made operational within cloud-native DevSecOps environments. Rather than offering or proposing new security primitives, the focus of this paper will be on how to integrate current security controls—secure build isolation, artifact integrity verification, policy-as-code enforcement, Kubernetes native admission controls, runtime monitoring, and AI assisted detection —into every day DevSecOps processes. This paper will provide an analysis of how the integration of these controls can be applied continuously throughout the entire process (build, release, deploy, run) without impacting developers' ability to complete tasks.Through connecting the supply chain security mechanisms to tangible operational points-of-contact, this research will offer practical direction on how to implement defense-in-depth within real world cloud-native pipelines. Finally, the paper will outline operational challenges, organizational considerations, and future directions to sustain secure and resilient software supply chains in increasingly automated and AI enabled environments.
Devamanoharan Dinesh Kumar (Wed,) studied this question.