Cloud, Containers & Security • Adrian Mouat, Kief Morris & Sam Newman • GOTO 2025

Cloud, Containers & Security • Adrian Mouat, Kief Morris & Sam Newman • GOTO 2025

🎙 GOTO Conferences 👥 1.1M 📅 June 15, 2026 ⏱ 44 min 👁 747 📄 expert opinion 🧭 2026-08-02
Available in: English (current) Français

Keywords

cloudcontainerssecuritysupply chaininfrastructure as codeAI

Summary

This interview, recorded at GOTO Copenhagen 2025, features Sam Newman interviewing Adrian Mouat (Chainguard) and Kief Morris (ThoughtWorks) on the current state and future of cloud, containers, and security. The discussion covers lessons learned from cloud adoption, the maturity of container technology, security challenges in cloud-native environments, and the impact of AI on infrastructure automation. Adrian highlights the evolution of container security, mentioning Sigstore for image signing and the ongoing issues with software supply chain attacks, such as the Jaguar Land Rover incident. Kief discusses the role of infrastructure as code and how AI is being integrated into infrastructure automation, noting both opportunities and concerns about determinism. The panel also addresses audience questions on SBOMs, package repositories, and the practical challenges of implementing security measures. The conversation emphasizes the need for short-lived tokens, verified sources, and the importance of community-driven security tools.

142 words

Critical Evaluation

The interview provides valuable insights from practitioners with deep experience in cloud and container technologies. Adrian Mouat and Kief Morris offer practical perspectives on security and infrastructure automation, grounded in their work at Chainguard and ThoughtWorks. The discussion is candid, touching on real-world incidents like the Jaguar Land Rover supply chain attack and the challenges of SBOMs. However, the format is informal, and claims are often anecdotal without formal citations. The panelists do not provide detailed technical explanations, making it less suitable for a deep technical audience. The conversation also lacks a critical examination of the limitations of AI in infrastructure, with Kief’s concerns about determinism not fully explored. Overall, the content is informative for practitioners seeking an overview of current trends, but it lacks the rigor of a formal technical talk. The title accurately reflects the content, and the discussion stays on topic. The presence of a brief promotional mention of books and products does not detract from the substance.

161 words

Title / Content Match

The title accurately reflects the content: a panel discussion on cloud, containers, and security, with a focus on current trends and future directions.

Quality & Reliability

7/10

Discussion among recognized experts in cloud, containers, and infrastructure, with practical insights and references to real-world incidents. However, it is an informal interview without formal citations or peer-reviewed sources, and some claims are anecdotal.

Chapters

Cited Sources

Concurring Sources

  • Sigstore — Open-source project for signing software artifacts, mentioned as a solution for container image signing.
  • NTIA SBOM — US government initiative promoting SBOMs, aligning with the discussion on supply chain security.

Dissenting Sources

  • Dan Lorenc on SBOMs — Adrian mentions that Dan Lorenc is skeptical about the usefulness of SBOMs, which contrasts with the general push for SBOM adoption.

External References

Contribution & Novelties

The interview provides a current snapshot of the cloud-native landscape from three experienced practitioners, highlighting emerging trends like the use of Sigstore for container signing and the challenges of SBOMs. It offers practical advice on supply chain security, such as eliminating long-lived tokens and using trusted publishers. The discussion on AI in infrastructure automation is timely, though it remains at a high level.

Pour aller plus loin :

  • Sigstore — The software signing project mentioned for securing container images.
  • Software Bill of Materials (SBOM) — NTIA page explaining SBOMs and their role in supply chain security.
  • Infrastructure as Code — Kief Morris’s book website, a key reference for infrastructure automation.
  • Chainguard — Company focused on secure container images and supply chain security.
  • Trusted Publishers — GitHub documentation on trusted publishers for npm.

132 words

Radar Profile

The radar profile shows balanced scores across information quantity, quality, technical depth, and reliability, with a slight emphasis on quality and reliability. This reflects a discussion that is informative and credible, though not deeply technical.

Reliability 7/10

💬 No comments were provided for analysis.