DevConf.US 2026

Security Process Improvements in Ceph and Rook ​
2026-09-24 –, 106 (Capacity 45)

We will cover recent improvements to our security model and process for Ceph and Rook, from dependency tracking to ensuring fixes are done within a timely fashion. The audience can expect to learn about the upstream and downstream processes, from reporting to disclosure and fix, as well as recent improvements to our threat model and architecture, including hardening options, MFA implementation, and recent encryption changes.

In a world with many chained dependencies requiring remediation, this work is essential to ensure compliance with modern executive orders, and to that end, we are also working to automate our processes. We aim to strengthen the Ceph Ecosystem with our collaborative approach by seeking feedback from attendees about how to improve our process going forward, and ensuring we have a practical upstream first security approach.


What level of experience should the audience have to best understand your session?: Intermediate - attendees should be familiar with the subject
See also: presentation slides (2.2 MB)

Gabriella joined IBM Storage Ceph's product security team in 2024, working to keep the product secure and finding ways to streamline its security processes. Gabriella graduated from Boston University in 2022, and in her free time enjoys exploring her hometown of NYC and eating sweets.