# 2017-06-19: Orchestration Security SIG meeting

**URL:** <https://forums.mobyproject.org/t/2017-06-19-orchestration-security-sig-meeting/90>\
**Category:** orchestration-security\
**Created:** [June 26, 2017, 4:45pm UTC](https://forums.mobyproject.org/t/2017-06-19-orchestration-security-sig-meeting/90 "2017-06-26T16:45:57Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![diogomonica](https://yyz1.discourse-cdn.com/flex031/user_avatar/forums.mobyproject.org/diogomonica/32/63_2.png) [@diogomonica](https://forums.mobyproject.org/u/diogomonica)\
**Post date:** [June 26, 2017, 4:45pm UTC](https://forums.mobyproject.org/t/2017-06-19-orchestration-security-sig-meeting/90/1 "2017-06-26T16:45:57Z")

</div>

Last week we had an Orchestration Security SIG meeting in person meeting at the Moby summit. Here is a quick recap on what we talked about:

- Linkerd lack of hitless updates between versions
- ISTIO guarantees/overlap over firewalls
- Side-car deployment model for Layer 7 proxies VS direct application-to-application security
- Service identities, certificate formats, SPIFFE identities
- The need for network-based IDS’s VS System-call monitoring
- External secrets project goals, current status, next steps
  - Gemalto HSM as a potential secret plugin.

- Quick update on entitlements

### Next Steps

- Gemalto to join the external secrets SIG
- New members to join the orchestration-sec channel, and start reviewing the docs
- Clarity around ISTIO plan for swarm for all attendees

- Next meeting scheduled for 10am PST July 5th.

## Other info

- Meeting notes: [https://docs.google.com/document/d/1co6Jv9Mq8jeToK-sYNNXwUQiPWcDCvlNJ5bozAOfriE/](https://docs.google.com/document/d/1co6Jv9Mq8jeToK-sYNNXwUQiPWcDCvlNJ5bozAOfriE/)
- #orchestration-sec on [dockercommunity.slack.com](http://dockercommunity.slack.com)
