Docker layers can be fast for developers but are also vulnerable if not audited for production. Wouldn’t it be great to improve continuous integration with continuous vulnerability detection?
Clair, a new open source tool to monitor the security of containers, is an API-driven analysis engine that inspects containers layer-by-layer for known security flaws. Joey Schorr and Quentin Machu offer an overview of Clair and use a real-life example to demonstrate how to apply Clair and how it’s able to automatically detect new and existing vulnerabilities in Docker and rkt containers before they get exploited, using graph database queries to track package changes. Come see how it works, get started using Clair to easily build services that provide continuous monitoring for container vulnerabilities, and learn how to get involved with the development.
Joey Schorr is a lead software engineer on the Quay team at CoreOS. Joey was cofounder of DevTable, a company he started after leaving Google to focus on building a web-based IDE, which was acquired by CoreOS.
Quentin Machu is an engineer on the Quay team at CoreOS and a maintainer of the Clair open source project, which scans containers for vulnerabilities. He is passionate about software engineering and distributed systems. Quentin completed an award-winning OpenStack project as part of his master’s in computer engineering.
©2016, O'Reilly Media, Inc. • (800) 889-8969 or (707) 827-7019 • Monday-Friday 7:30am-5pm PT • All trademarks and registered trademarks appearing on oreilly.com are the property of their respective owners. • firstname.lastname@example.org