Booz Allen trusts Chainguard to harden critical infrastructure for the National Weather Service

The challenge

Ingesting roughly 30 terabytes of data per day from numerical weather models, satellite, radar, and ground observation systems, CIRRUS is the operational data backbone for the National Weather Service (NWS). Forecasters rely on it not just for climate data and forecasts, but also to issue life-safety warnings and advisories, such as tornado, hurricane, flood, and winter storm alerts. Its High Value Asset designation means the platform must meet a demanding combination of low latency and high reliability.

Jose Plascencia, Platform Lead for the NWS CIRRUS program at Booz Allen, is on the team responsible for building that platform from the ground up. Early in the project, the security leads at NWS pressed the Booz Allen team on a direct question: “If you're building on open source tooling, how do you know it isn't quietly introducing vulnerabilities, and what's your plan for keeping it current?”

Using Booz Allen's internal Kubernetes deployment accelerator, Jose’s team could deploy tooling quickly, but they'd still pull from public open source containers. Keeping those images patched and current would have meant constantly re-evaluating versions, testing alternate base images, and manually tracing the downstream effects of every swap.

The solution

Rather than absorb that ongoing burden, Jose’s team turned to Chainguard. Booz Allen signed an Enterprise License Agreement with Chainguard, giving its more than 6,000 engineers access to Chainguard Containers and Libraries. For the NWS CIRRUS team, that meant a direct path to hardened, continuously rebuilt container images with zero known CVEs, without having to build custom registries or absorb the cost of an enterprise open source support license on their own.

With that foundation in place, the swap was straightforward. Jose’s team set up a proxy through their Harbor registry to Chainguard's repository, then worked through their existing infrastructure-as-code to replace open source image references with Chainguard equivalents.

Jose and the team saw results immediately after an early swap of Keda. “It took about 20 minutes of a junior developer's time to find the image, replace it, test it, and we didn’t have to make any changes,” he said. “We realized, ‘wow, we can go from CVEs to no CVEs and not have to change much at all.’”

The team extended the same approach to their CI/CD pipeline, replacing the images running their build and test tooling, including linters and package managers, in under a week. Rather than a disruptive migration, it was a series of low-friction, drop-in replacements that let engineers move on to the next tool instead of being pulled into extended testing cycles.

“
We have everything as infrastructure as code, so we more or less just dropped in the repository reference from open source to Chainguard, and in almost all cases, that was it. We moved on to the next one because we found it just worked.
JOSE PLASCENCIA, PLATFORM LEAD FOR THE NWS CIRRUS PROGRAM AT BOOZ ALLEN

The results

A meaningful reduction in critical CVEs

The NWS CIRRUS team saw the impact quickly. When Jose’s team first ran a Trivy scan across their cluster, they counted roughly 1,400 critical vulnerabilities. After less than a month of working through their container image replacements, they saw a roughly 85% reduction.

When NWS security stakeholders raised their original question about how the team would manage open source risk, Jose’s team could point to a concrete before-and-after: the same version of a given piece of software, with and without Chainguard, and a clear trajectory toward zero known CVEs. “It’s been revealing to know how many CVEs would otherwise exist to us if we didn’t have a partnership and a path to get us to zero in most of these cases,” Jose said.

“
When we first pulled up our Trivy scanner, our jaws fell on the floor thinking, 'wow, that’s a lot of CVEs.’ Now that we’ve been implementing Chainguard, it’s ‘wow, that’s a lot fewer CVEs.’
JOSE PLASCENCIA, PLATFORM LEAD FOR THE NWS CIRRUS PROGRAM AT BOOZ ALLEN

Enterprise-grade support

The partnership between Booz Allen and Chainguard has reshaped how the team operates day to day. As Jose explained, “Not only do we have this partnership and access to the great organization and their processes, but they're also extremely receptive. It almost felt like we were getting enterprise service support for open source tools without having to pay for an enterprise version of the tool itself.”

Booz Allen's engineers have office hours scheduled with the Chainguard team, but in practice, Jose says the team rarely needs to wait for them. "The regular office hours with Chainguard are great because it gives us an opportunity to ask questions," he said. "But it's been funny, I didn't even realize we had office hours until later, because anytime we had a question, there was just an immediate offer to help."

“
It’s been comforting to see the level of support we’ve gotten with Chainguard if something doesn't work out of the box. It takes one Slack message, and before we know it, our Customer Success Manager is all over it.
JOSE PLASCENCIA, PLATFORM LEAD FOR THE NWS CIRRUS PROGRAM AT BOOZ ALLEN

A cultural shift in leveraging open source software

The ease of staying current on Chainguard's catalog has pushed the team toward a more disciplined update cadence overall: rather than deploying a tool and leaving it alone indefinitely, they're now more consistently evaluating upgrade paths, which Jose credits with keeping the team honest about their security posture as CIRRUS continues to scale.

“
We're constantly looking at what's available up to date, what's available in the Chainguard catalog, and upgrading along with them. It’s a forcing factor—we want to stay at zero CVEs, so that’s led to a good culture adjustment.
JOSE PLASCENCIA, PLATFORM LEAD FOR THE NWS CIRRUS PROGRAM AT BOOZ ALLEN

"In almost every case, you're just dropping and replacing," Jose said. "So why wouldn't you? You're going to save yourself CVEs, and you're going to get a security person off your back, and that's hard to do."

share this article

Booz Allen trusts Chainguard to harden critical infrastructure for the National Weather Service

Execute commandCG System prompt

$ chainguard learn --more

Contact us