3rd EOSC SIESTA webinar: A journey through the SIESTA computing infrastructure

Europe/Madrid
Judith Sainz-Pardo Diaz, Álvaro López García (IFCA)
Description

This webinar will present the key components of the EOSC SIESTA computing infrastructure, the dashboard, the process for deploying a catalog through pipelines, as well as security hardening in the cluster.

Live streaming at: https://www.youtube.com/watch?v=4ynyG15KaG0

Registration
Participants
    • 10:00 AM 10:30 AM
      SIESTA Providers view: Technological Foundation and Infrastructures 30m

      Building a confidential computing platform can be overwhelming given the variety of components required. This session explores the core technological pillars supporting the SIESTA infrastructure from the perspective of a platform provider. We examine the deployment process of a confidential computing environment based on Trusted Execution Environments (TEEs) and Confidential Containers (CoCo) plus all the different core and auxiliary services that are needed, using state-of-the-art tools such as Terraform, Ansible, and ArgoCD. These tools enable declarative infrastructure and automate configuration and state management. The aim of the session is to provide an architectural roadmap as well as a clear understanding of the essential toolstack required to begin deploying a platform like SIESTA.

      Speaker: Andres Heredia Canales (IFCA - CSIC)
    • 10:30 AM 11:00 AM
      SIESTA Users view: User interfaces and services 30m

      This presentation introduces the main user-facing components and services of the EOSC-SIESTA platform from the perspective of the end user. The session presents the Onyxia environment and its service catalogue approach based on Helm charts published through GitLab Pages, together with the integration of storage and secret management services.
      The talk also covers catalogue management through Keycloak groups and the interaction between deployed services and the underlying infrastructure components.

      Speaker: Saúl Fernández Tobías (IFCA - CSIC)
    • 11:00 AM 11:30 AM
      SIESTA Developers view: Development and Integration 30m

      The growing adoption of cloud-native technologies and distributed research infrastructures introduces challenges in cybersecurity, compliance, and operational resilience.
      The talk covers secure CI/CD pipelines with DevOps Catalogue, Policy-as-Code enforcement using Open Policy Agent (OPA), configuration validation with Conftest, automated code quality and vulnerability analysis with Sonar-based tooling, and secure artifact management using Nexus repositories. Special attention is given to container image signing and verification and secure software supply chain practices.
      The session summarizes practical lessons learned, integration challenges, and recommendations for EOSC-SIESTA use cases seeking to improve cybersecurity while maintaining operational flexibility and scalability.

      Speaker: Mikuláš Strelecký (Interway)