Designed and shipped a multi-stage report-protection workflow in Kubescape, evolving from deterministic anonymization of Kubernetes resource metadata into reversible encryption and decryption of sensitive report data.
Highlights:
- Kubernetes resource, container, and service-account anonymization
- Repository, Git, annotation, and filesystem metadata protection
- AES-GCM encryption and Data Encryption Key (DEK) wrapping
- Reversible resource and container metadata transformation
- Report decryption and CLI documentation
- Multiple upstream contributions shipped in Kubescape v4.0.11
๐ Read the full engineering case study โ ๐ Original Kubescape feature request โ ๐ Offical Docs โ ๐ Blog โ
Built a layered software supply-chain release-integrity workflow for Kubescape RegoLibrary, evolving artifact verification from SHA-256 checksums into an authenticated release-verification chain.
Highlights:
- SHA-256 verification of release artifacts
- Explicit
ErrChecksumVerificationsecurity boundary - Kubescape hard-failure behavior on checksum verification errors
- Cosign keyless signing of the release checksum manifest
- Sigstore bundle and signer identity verification
- Trusted-root handling with
LiveTrustedRoot sigstore-goupgrade and trusted-root refresh- Real GitHub Release integration testing
- Downstream consumption in Kubescape
- Released in RegoLibrary v2.0.36
๐ Read the full engineering case study โ
๐ง sumanmandal.dev@gmail.com




