Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Project] Security Pals, Assemble! #1102

Open
7 of 19 tasks
JustinCappos opened this issue Aug 2, 2023 · 5 comments
Open
7 of 19 tasks

[Project] Security Pals, Assemble! #1102

JustinCappos opened this issue Aug 2, 2023 · 5 comments

Comments

@JustinCappos
Copy link
Collaborator

JustinCappos commented Aug 2, 2023

Description: I'd like to run a pilot at NYU where I have a class of 100-150 students help CNCF projects get a self assessment completed. The students will work in groups and use the new Security Pals process to work with the projects.

Impact: Any CNCF projects at the graduated and incubating levels that have not either completed a self assessment (or opted out) will have a first pass at a self assessment completed. If we have enough effort, we will also extend this to cover sandbox projects.

Benefit to Ecosystem: Projects will gain an understanding of how understandable their documentation is and how welcoming their project is to newcomers, in addition to the aforementioned self assessment.

Scope: This will take a lot of effort from myself and the students at NYU, who will do this as part of a series of assignments in a graduate level introductory security class. Students will understand threat modeling and similar processes, but should not be expected to understand cloud native technologies in depth.

Note to Maintainers: The time per project for the project maintainers should be a few developer days worth of time answering questions. To help your project be successful, please be patient and welcoming when interacting with students. If you have a problem, please reach out to me sooner, rather than later and we can try to correct.

Expected Timeline: The work will be done over a duration of roughly 4 weeks (roughly mid-November - mid-December, dates TBA). Some students may want to stay engaged with projects after this period.

Ask from CNCF TOC: I would appreciate the TOC and others announcing this effort at upcoming KubeCon events to raise project awareness. I would also appreciate some CNCF communications being sent out at the start / end of this to further provide updates.

Ask from CNCF PR team: Also, NYU and the CNCF can collectively do PR related to this initiative.

Intent to lead: Justin Cappos

  • I volunteer to be a project lead on this proposal if the community is
    interested in pursing this work.
    This statement of intent does not preclude
    others from co-leading or becoming lead in my stead.

Proposal to Project:

  • Added to the planned meeting template for August 1st, 2023
  • Raised in a Security TAG meeting to determine interest - August 1st, 2023
  • Collaborators comment on issue for determine interest and nominate project
    lead
  • Scope determined via meeting mm dd and/or shared document add link
    with call for participation in #tag-security slack channel thread add link
    and mailing list email add link
  • Scope presented to Security TAG leadership and Sponsor is assigned

TO DO

  • Security TAG Leadership Representative: @sublimino & @PushkarJ
  • Project leader(s): @JustinCappos
  • Issue is assigned to project leaders and Security TAG Leadership
    Representative
  • Project Members:
  • Fill in addition TODO items here so the project team and community can
    see progress!
  • Scope
  • Deliverable(s)
  • Project Schedule
  • Slack Channel (as needed)
  • Meeting Time & Day:
  • Meeting Notes (link)
  • Meeting Details (zoom or hangouts link)
  • Retrospective
@JustinCappos JustinCappos added proposal common precursor to project, for discussion & scoping triage-required Requires triage labels Aug 2, 2023
@caniszczyk
Copy link
Contributor

This is awesome, is there anything we can do for some of the students who participate in the program? Swag? Encourage them to apply for scholarships for kubecon etc?

@JustinCappos
Copy link
Collaborator Author

This is awesome, is there anything we can do for some of the students who participate in the program? Swag? Encourage them to apply for scholarships for kubecon etc?

Both / either would be appreciated! There will be ~120 or so students and the quality of their work will likely vary. Let me know if you want to have any selection process, etc. for some aspects of this.

I don't know how much you're thinking of doing here. I think it would be great to have t-shirts for all and maybe fast track students that participate after the end of the assignment for Kubecon scholarships... I'm open to whatever makes sense from your side.

@ragashreeshekar
Copy link
Collaborator

ragashreeshekar commented Aug 3, 2023

Great initiative @JustinCappos
I'm interested to collaborate in the capacity necessary for assessments, technical mentorship, program management etc.

@JustinCappos
Copy link
Collaborator Author

Great initiative @JustinCappos I'm interested to collaborate in the capacity necessary for assessments, technical mentorship, program management etc.

Okay, great. It will be great to have some folks from the CNCF side willing to guide parts of this. Even if it is only to help train the TAs, this will be a huge help!

@Rana-KV
Copy link
Contributor

Rana-KV commented Sep 20, 2023

Hi all,
I'm the course assistant for @JustinCappos. I would be working on security self assessment of Karmada. As part of this process, I will initiate an issue for the self-assessment within the TAG-security repository and another one within the Karmada project repository to keep them in the loop.

@mnm678 mnm678 added in-progress and removed proposal common precursor to project, for discussion & scoping triage-required Requires triage labels Oct 18, 2023
@anvega anvega changed the title [Proposal] Security Pals, Assemble! [Project] Security Pals, Assemble! Oct 18, 2023
@PushkarJ PushkarJ added this to Active Projects in Roadmap 2024 Jan 19, 2024
@PushkarJ PushkarJ added this to the STAG Rep: @JustinCappos milestone Apr 24, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Roadmap 2024
Active Projects
Development

No branches or pull requests

6 participants