We will cover recent improvements to our security model and process for Ceph and Rook, from dependency tracking to ensuring fixes are done within a timely fashion. The audience can expect to learn about the upstream and downstream processes, from reporting to disclosure and fix, as well as recent improvements to our threat model and architecture, including hardening options, MFA implementation, and recent encryption changes.
In a world with many chained dependencies requiring remediation, this work is essential to ensure compliance with modern executive orders, and to that end, we are also working to automate our processes. We aim to strengthen the Ceph Ecosystem with our collaborative approach by seeking feedback from attendees about how to improve our process going forward, and ensuring we have a practical upstream first security approach.