Ortelius: A Supply-Chain Evidence Catalog for Microservices

Shriira Press

Preface

A unified evidence store that answers the question every platform team eventually asks: what version of what is running where, and what is wrong with it right now?

Welcome to Ortelius: A Supply-Chain Evidence Catalog for Microservices.

Ortelius is an open-source supply-chain evidence catalog maintained by the Continuous Delivery Foundation. It exists to solve a problem that microservices created and that nobody planned for: once an application is decomposed into dozens of independently built, independently deployed components, the knowledge of what those components are, what they depend on, and where they run scatters across pipelines, registries, and clusters until no single person or tool can answer a simple security question. Ortelius gathers that scattered evidence into one place. It ingests SBOMs and build metadata as components are produced, aggregates per-component bills of materials into a complete picture of a logical application, versions that application automatically as its parts change, records where every release is deployed, and continuously correlates the whole inventory against live vulnerability intelligence so it always knows which running deployments are exposed. This book walks through that story from the ground up. The early chapters explain the microservices problem and the evidence-catalog idea that answers it; the middle chapters cover the data model, SBOM aggregation, automatic application versioning, the digital twin of your running estate, and continuous CVE correlation; the later chapters show how Ortelius plugs into a CI/CD pipeline through its CLI, and close with practical guidance on adopting it and where it sits in the wider supply-chain security ecosystem.

This title is part of the ShriIra library and is free to read in full, right here — our small contribution to making world-class knowledge easy to reach.

A note on reading it: open the Contents menu at the top of the reader to jump between chapters, use the Aa menu to set a comfortable text size, theme (light, sepia, or night), and single- or two-page layout. Your place is saved automatically, so you can always pick up where you left off.

We hope it serves you well.

— Shriira Press

Contents

  1. Chapter 1 — The Microservices Evidence Problem
  2. Chapter 2 — What Ortelius Is
  3. Chapter 3 — The Data Model: Components, Applications, and Endpoints
  4. Chapter 4 — Aggregating SBOMs
  5. Chapter 5 — Versioning Applications Made of Microservices
  6. Chapter 6 — The Digital Twin and Continuous CVE Correlation
  7. Chapter 7 — Feeding Ortelius from the Pipeline
  8. Chapter 8 — Ortelius in Practice
0%
1/1