VOOZH about

URL: https://thenewstack.io/container-security-and-ai-a-talk-with-chainguards-founder/

⇱ Container Security and AI: A Talk With Chainguard's Founder - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2025-04-22 06:00:41
Container Security and AI: A Talk With Chainguard's Founder
podcast,sponsor-chainguard,sponsored-podcast,video,
AI / Containers / Security

Container Security and AI: A Talk With Chainguard’s Founder

Ville Aikas, an early contributor to Kubernetes and other open source projects, discussed keeping containers secure in this episode of The New Stack Makers.
Apr 22nd, 2025 6:00am by Michelle Gienow
👁 Featued image for: Container Security and AI: A Talk With Chainguard’s Founder
Chainguard sponsored this post.

In this On the Road episode of The New Stack Makers, TNS Publisher and Founder Alex Williams caught up with Ville AikasChainguard founder and self-described “first contributor to Kubernetes before it was even Kubernetes.”

The discussion, recorded at KubeCon  + CloudNativeCon Europe, in London, ranged from the historical context of container security (and early assumptions about secure behavior that were later proven incorrect) to what container image security looks like in AI/machine learning environments.

Aikas, who worked on early open source projects including Kubernetes, Helm, and Knative, described how fundamental security principles were sometimes overlooked in the rush to enable functionality. “Secure defaults are really important, and that’s something that I think that we didn’t quite get right,” Aikas said, noting that configurations like running containers as root should have required special permissions rather than being the default behavior:

“We were pushing demo images to Docker and then running them from there because we didn’t have a container registry at the time,” he said. Someone asked “‘Wait, so people can just pull these things? How do you validate them?’ and we’re like, well, of course, nobody’s going to pull just random stuff. They’re going to validate.”

Looking back, Aikas said, some cognitive bias was a work. “We’re all within Google, where you couldn’t do things like that because everything was locked down the right way. So we assumed that other people would also have very good security posture,” he recalled. “It turns out that wasn’t always the case.”

Lessons Learned and Emerging Challenges

The Kubernetes community did more than establish secure defaults, Aikas said: It worked to create governance policies and collaborated on best practices around standardized security scanning, addressing issues like ephemerality, avoiding long-lived credentials, and federated authentication.

At the same time, though, Aikas also saw companies expressing the desire to, as he puts it “get the container images that you love from a place that you can trust.”

Aikas founded Chainguard to meet this need, providing “minimal, zero CVE container images” built with transparent tool chains, full software bills of materials (SBOMs) and reproducibility. “You can trust us, but you can also verify us,” he said.

This same philosophy extends to Chainguard’s virtual machine offering for container hosts and its recently released Chainguard Libraries, which brings the same security principles to application dependencies, starting with Java packages. “Our users, their core competency is building software and running software, not chasing security issues,” he said.

The conversation moved on to emerging challenges, starting with a talk by Chainguard’s Wojciech Kocjan on container security in AI/ML Kubernetes environments at Cloud Native Rejekts.

“More and more trust is starting to be put into those systems, but there’s very little knowledge on where they came from, right?” Aikas pointed out. The complexity multiplies with GPU integration, different model versions and potential attack vectors unique to AI, where even a tiny change to input data can dramatically alter outputs.

The need for securing models is getting a lot of attention in the open source community, Aikas said, and also at Chainguard. “We moved to providing locked-down, guarded AI images so people can run their workloads knowing that at least the [ML] code is more secure.”

Check out the full episode to hear more about container image supply chains, the challenges of measuring container security effectiveness, and a deeper exploration of emerging AI-driven development security concerns.

Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk.
Learn More
The latest from Chainguard
Hear more from our sponsor
TRENDING STORIES
Michelle Gienow is a former journalist turned software developer. She draws from both professions to write about in-depth technical topics ranging from K8s to Kotlin. Michelle is co-author of "Cloud Native Transformation: Practical Patterns for Innovation" from O'Reilly Media and...
Read more from Michelle Gienow
Chainguard sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Docker.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.