Topic library

Cloud security & platform engineering topics

Follow a topic to find focused talks, incident analysis, implementation guidance, videos, slides, and repositories drawn from production cloud and security work.

Browse every topic

These topic pages connect related conference sessions and make the full archive easier to explore.

Security

5 talks

Conference talks and case studies spanning cloud security, Kubernetes security, software supply chains, and incident response.

Cloud security talks and case studies covering AWS, CNAPP, posture management, risk prioritization, detection, and runtime protection.

CloudNativeCon sessions on building and protecting cloud-native systems with open standards and CNCF tooling.

KubeCon

2 talks

KubeCon talks on Kubernetes, SLSA, artifact integrity, policy enforcement, and cloud-native supply chain security.

Hands-on guidance for SLSA, Sigstore and Cosign, build provenance, attestations, admission policy, and secure CI/CD.

Wiz

2 talks

Real-world Wiz and CNAPP lessons for cloud visibility, contextual risk prioritization, shift-left security, and runtime detection.

AWS

1 talk

AWS cloud security talks covering posture management, runtime protection, detection, and practical controls for production environments.

Sessions presented at AWS Summit, with field-tested lessons for securing cloud infrastructure from code through runtime.

Practical approaches to cloud and software compliance that turn policy requirements into repeatable engineering controls.

Infrastructure security lessons from protecting cloud systems and digital-asset products in a highly targeted industry.

JavaScript ecosystem security, including dependency risk, npm compromise patterns, and safer package delivery pipelines.

Ledger

1 talk

Public talks and case studies about cloud security, platform reliability, and developer security practices at Ledger.

npm

1 talk

Analysis of npm supply chain attacks and practical guidance for trusted publishing, lockfiles, tokens, and dependency monitoring.

OWASP

1 talk

OWASP community sessions focused on current application-security incidents and controls engineering teams can apply.

Phishing

1 talk

Security incident analysis showing how phishing can compromise maintainers, packages, CI/CD credentials, and downstream users.

Research and talks on dependency compromise, artifact trust, package ecosystems, and end-to-end software supply chain defense.