Uploaded November 2025 | Updated September 2026, 2 weeks ago
Security Process Improvements in Ceph and Rook - Sage McTaggart & Gabriella Roman, IBM
We will cover recent process improvements to our security model and process for Ceph and Rook, from dependency tracking to ensuring fixes are done within a timely fashion. We will have a brief summary of the security model in Ceph as well.
By going over our process from reporting to disclosure and fix, in upstream and downstream the audience will gain information about our improved process and disclosure, and understand our recent threat model and architecture improvements. We will also cover hardening options and recent improvements to secure architecture within Ceph, ranging from Dashboard improvements with MFA, to recent encryption changes for more secure data, and seek feedback on how to improve our process through future iterations.
In a world with many chained dependencies requiring remediation, this work is essential to ensure compliance with modern executive orders, and to that end, we are working to automate our processes. We will better the Ceph Ecosystem with our collaborative approach, including seeking feedback from attendees about how to improve our process going forward, and ensure we have a practical upstream first security approach.
Security Process Improvements in Ceph and Rook - Sage McTaggart & Gabriella Roman, IBM
We will cover recent process improvements to our security model and process for Ceph and Rook, from dependency tracking to ensuring fixes are done within a timely fashion. We will have a brief summary of the security model in Ceph as well.
By going over our process from reporting to disclosure and fix, in upstream and downstream the audience will gain information about our improved process and disclosure, and understand our recent threat model and architecture improvements. We will also cover hardening options and recent improvements to secure architecture within Ceph, ranging from Dashboard improvements with MFA, to recent encryption changes for more secure data, and seek feedback on how to improve our process through future iterations.
In a world with many chained dependencies requiring remediation, this work is essential to ensure compliance with modern executive orders, and to that end, we are working to automate our processes. We will better the Ceph Ecosystem with our collaborative approach, including seeking feedback from attendees about how to improve our process going forward, and ensure we have a practical upstream first security approach.










