Securing our software supply-chain better with reproducible builds for enclaves

Hello! I am Nico, part of the Engineering team within Security here at Monzo :building_construction:

In order to keep our customers safe, we put a lot of care in protecting some of our most sensitive workloads by running them inside AWS’ secure enclaves. We have recently learnt a lot about protecting these against supply chain attacks, specifically by achieving bit-by-bit reproducible builds. To do this, we have adopted Nix :snowflake: , an alternative to Docker for build environments.

Our new approach is radically different from AWS’ and it gives us even more confidence that we keep our infrastructure secure. So we decided to write about it and open source it! You can find the blog here:

Feel free to ask me anything!

20 Likes

‘Tom’ has a good point - it’s a valid [anything] question which can be dropped here.

2 Likes