in-toto
in-toto is a framework for proving that a software release passed through the expected supply-chain steps, performed by authorized people or systems, without unauthorized artifact changes.
itCloud native tools and technologies | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic - in-toto
in-toto centers on in-toto. in-toto is a framework for securing software supply-chain integrity. It gives a consumer evidence about how a release moved from source and build work to a delivered artifact.
Operate from the project's own resources and APIs. Learn how desired state becomes running state, which status conditions matter, and which dependencies (network, storage, identity, certificates) the control plane assumes.
Upgrades, backups, and credential rotation are part of the product, not optional aftercare. Version skew between clients and servers creates failures that look like application bugs. Pin versions and rehearse rollback.
Convenience features reduce boilerplate and widen blast radius. Enable them when you can observe and reverse the expanded surface. Defaults from quickstarts are starting points, not production policy.
Name owners for upgrades, credentials, and disaster recovery before traffic arrives. Unowned control-plane state becomes an outage with no clear pager. Prefer explicit version pins and tested rollback over floating tags that quietly change behavior between deploys.
Name owners for upgrades, credentials, and disaster recovery before traffic arrives. Unowned control-plane state becomes an outage with no clear pager. Prefer explicit version pins and tested rollback over floating tags that quietly change behavior between deploys.
Name owners for upgrades, credentials, and disaster recovery before traffic arrives. Unowned control-plane state becomes an outage with no clear pager. Prefer explicit version pins and tested rollback over floating tags that quietly change behavior between deploys.
Read the Intro for the mental model. Use the Cheatsheet when you need the resource map. Updates and Upstream track the in-toto release line that changes these APIs.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://in-toto.io/
Supports
- in-toto as a framework for securing software supply-chain integrity
- The goal of making performed steps, actors, and order transparent
- https://in-toto.io/docs/getting-started/
Supports
- Signed layouts defining steps and authorized functionaries
- Signed link metadata for commands, materials, products, and functionaries
- Artifact-rule types and the default behavior for unmatched artifacts
- in-toto-run, in-toto-record, in-toto-sign, and in-toto-verify
- Inputs required for final-product verification
- https://github.com/in-toto/docs/blob/master/in-toto-spec.md
Supports
- Roles of project owner, functionary, and client
- Layout, link, artifact, material, product, and verification definitions
- Link metadata structure and supply-chain workflow
- Artifact-rule semantics and cross-step relationships
- https://in-toto.io/docs/specs/
Supports
- Stable in-toto specification availability
- Stable in-toto Attestation Framework specification availability
- https://in-toto.readthedocs.io/en/stable/
Supports
- Python reference implementation scope
- Available evidence-generation and verification tooling
- Metadata-model and layout-creation documentation
- https://in-toto.readthedocs.io/en/stable/command-line-tools/in-toto-verify.html
Supports
- Layout signature and expiry checks
- Link thresholds, authorized functionary signatures, and artifact-rule checks
- Sequential execution of inspection commands
- Required verification key and optional link-directory inputs
- https://github.com/bureado/awesome-software-supply-chain-security
Supports
- Discovery of adjacent supply-chain security projects for awesome links
- https://slsa.dev/
Supports
- SLSA as an adjacent supply-chain security framework
- https://www.sigstore.dev/
Supports
- Sigstore signing and verification infrastructure
- https://github.com/guacsec/guac
Supports
- GUAC collection and query of software-supply-chain metadata
