Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Translation of Cloud Native Security White Paper(Chinese) #470 #471

Merged
merged 10 commits into from
Feb 26, 2021

Conversation

babysor
Copy link
Contributor

@babysor babysor commented Nov 29, 2020

According to proposal #470 , we conducted a Chinese translation and review of Cloud Native Security White Paper. Thanks to the amazing teamwork and Jimmy's initiating.

@Gsealy
Copy link

Gsealy commented Nov 30, 2020

@rootsongjc @babysor
about Encryption part, I have retranslate it try to read more fluently.
PTAL

#### 加密

对容器镜像进行加密,从而保证镜像内容的机密性。加密后,以确保它们从构建到运行前都是密文态。当加密镜像分发后受到破解,制品库中存储的镜像仍然是加密的,这有助于保护商业机密或其他保密材料等。

容器镜像加密的另一个常见用途是容器镜像授权的增强。当镜像加密与密钥证明管理和/或授权、认证发布等相结合时,可以要求容器镜像只能在特定平台上运行。容器镜像授权也适合保证合规性,例如地理限制、出口管控和数字版权媒体管理。

@rootsongjc
Copy link
Member

@rootsongjc @babysor
about Encryption part, I have retranslate it try to read more fluently.
PTAL

#### 加密

对容器镜像进行加密,从而保证镜像内容的机密性。加密后,以确保它们从构建到运行前都是密文态。当加密镜像分发后受到破解,制品库中存储的镜像仍然是加密的,这有助于保护商业机密或其他保密材料等。

容器镜像加密的另一个常见用途是容器镜像授权的增强。当镜像加密与密钥证明管理和/或授权、认证发布等相结合时,可以要求容器镜像只能在特定平台上运行。容器镜像授权也适合保证合规性,例如地理限制、出口管控和数字版权媒体管理。

可以使用这个翻译替换下。

@lumjjb
Copy link
Collaborator

lumjjb commented Nov 30, 2020

Thanks @babysor , @rootsongjc, @Gsealy! This is really great! I think that if there is a consensus among the 3 of you that it is good, then we can go ahead and approve this.

I would add a couple asks:

  • Can we add a link to the version that is being translated. Want to make sure that we keep that information in case we need to make edits to the whitepaper that need to be propagated. We can link to a commit ID of the github repo.
  • For the authors, seems like there's a mix, I think let's keep it all the same or add brackets for translation of names.


## 云原生目标

容器和微服务架构的采用和革新带来了不少挑战。在现代化组织中,减少网络安全漏洞的需求优先级已经成明显趋势地攀升。同时,随着围绕云应用的创新加速,新的威胁状况也在增加。安全领导层需要通过采取预防、检测和应对网络威胁等措施、满足严格的合规要求,来完成他们身上背负的“保护包括人力 [4] 和非人力资产”任务。然而,有个常见的旧说法,指责这些安全措施阻碍了 DevOps 团队的速度和敏捷性。因此,安全领导层必须搭建起更紧密的集成和互相理解的通道,在为 DevOps 团队赋能更多的同时,使得其能有共同抵御网络风险的责任心。
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

安全领导层 -> 安全行业领袖

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

这里应该指组织内的安全leaders(例如CSO)吧

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

啊,我以为是说业界要赶紧发展通用方案,这样企业才愿意跟进

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

因为段落的第二句说了 “在现代化的组织中”,我读下来是在这个scope内的,你觉得呢?


#### 仓库隔离

由于使用的开放源码组件往往是从公共来源中提取的。各组织应在其流水线中,创建不同阶段的仓库。只有已授权的开发人员才能访问公共仓库和拉动基础镜像,然后将其存储在内部仓库中,以便在组织内部广泛使用。此外,还建议有单独的私有仓库,用于保存每个团队或小组的开发工件,最后还有一个暂存或预生产仓库,用于准备生产的镜像。这样可以对开源组件的来源和安全性进行更严格的控制,同时可以对 CI/CD 的各个阶段进行不同类型的测试。

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

s/拉动/拉取

这样比较符合习惯吧

@lumjjb
Copy link
Collaborator

lumjjb commented Jan 5, 2021

Once we are 90% there we can merge it in and it will be a living document and we can update it as we go. Any thoughts on where we are on this? There's a lot of good work already in this, would like to merge it soon if we think it's ready so we can share it to a wider audience!

Copy link
Collaborator

@lumjjb lumjjb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! This looks really good and looking forward to sharing this with the rest of the community!
Big thank you to everyone! @rootsongjc, @N3erox0, @cafra, @aiaicaow, @hbrls, @Losery, @knwng, @babysor, @gtb-togerther, @dwctua

A couple minor things, which can be included in this PR or a separate one:

@lumjjb lumjjb merged commit 8860771 into cncf:master Feb 26, 2021
@PushkarJ PushkarJ mentioned this pull request Aug 10, 2021
21 tasks
Michael-Susu12138 pushed a commit to Michael-Susu12138/tag-security that referenced this pull request Dec 12, 2023
…ncf#471)

* Translation of Cloud Native Security White Paper(Chinese) cncf#470

* Re-format according to review

* Skip translation of author names, and use translation from @Gsealy!

* Remove duplicate and fix some nits

* remove duplicate

* fix nits

Co-authored-by: Emily Fox <33327273+TheFoxAtWork@users.noreply.github.com>
Co-authored-by: Vega Chen <babysor>
Co-authored-by: Brandon Lum <lumjjb@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

9 participants