Booz Allen trusts Chainguard to harden critical infrastructure for the National Weather Service
The challenge
Ingesting roughly 30 terabytes of data per day from numerical weather models, satellite, radar, and ground observation systems, CIRRUS is the operational data backbone for the National Weather Service (NWS). Forecasters rely on it not just for climate data and forecasts, but also to issue life-safety warnings and advisories, such as tornado, hurricane, flood, and winter storm alerts. Its High Value Asset designation means the platform must meet a demanding combination of low latency and high reliability.
Jose Plascencia, Platform Lead for the NWS CIRRUS program at Booz Allen, is on the team responsible for building that platform from the ground up. Early in the project, the security leads at NWS pressed the Booz Allen team on a direct question: “If you're building on open source tooling, how do you know it isn't quietly introducing vulnerabilities, and what's your plan for keeping it current?”
Using Booz Allen's internal Kubernetes deployment accelerator, Jose’s team could deploy tooling quickly, but they'd still pull from public open source containers. Keeping those images patched and current would have meant constantly re-evaluating versions, testing alternate base images, and manually tracing the downstream effects of every swap.
The solution
Rather than absorb that ongoing burden, Jose’s team turned to Chainguard. Booz Allen signed an Enterprise License Agreement with Chainguard, giving its more than 6,000 engineers access to Chainguard Containers and Libraries. For the NWS CIRRUS team, that meant a direct path to hardened, continuously rebuilt container images with zero known CVEs, without having to build custom registries or absorb the cost of an enterprise open source support license on their own.
With that foundation in place, the swap was straightforward. Jose’s team set up a proxy through their Harbor registry to Chainguard's repository, then worked through their existing infrastructure-as-code to replace open source image references with Chainguard equivalents.
Jose and the team saw results immediately after an early swap of Keda. “It took about 20 minutes of a junior developer's time to find the image, replace it, test it, and we didn’t have to make any changes,” he said. “We realized, ‘wow, we can go from CVEs to no CVEs and not have to change much at all.’”
The team extended the same approach to their CI/CD pipeline, replacing the images running their build and test tooling, including linters and package managers, in under a week. Rather than a disruptive migration, it was a series of low-friction, drop-in replacements that let engineers move on to the next tool instead of being pulled into extended testing cycles.
The results
A meaningful reduction in critical CVEs
The NWS CIRRUS team saw the impact quickly. When Jose’s team first ran a Trivy scan across their cluster, they counted roughly 1,400 critical vulnerabilities. After less than a month of working through their container image replacements, they saw a roughly 85% reduction.
When NWS security stakeholders raised their original question about how the team would manage open source risk, Jose’s team could point to a concrete before-and-after: the same version of a given piece of software, with and without Chainguard, and a clear trajectory toward zero known CVEs. “It’s been revealing to know how many CVEs would otherwise exist to us if we didn’t have a partnership and a path to get us to zero in most of these cases,” Jose said.
Enterprise-grade support
The partnership between Booz Allen and Chainguard has reshaped how the team operates day to day. As Jose explained, “Not only do we have this partnership and access to the great organization and their processes, but they're also extremely receptive. It almost felt like we were getting enterprise service support for open source tools without having to pay for an enterprise version of the tool itself.”
Booz Allen's engineers have office hours scheduled with the Chainguard team, but in practice, Jose says the team rarely needs to wait for them. "The regular office hours with Chainguard are great because it gives us an opportunity to ask questions," he said. "But it's been funny, I didn't even realize we had office hours until later, because anytime we had a question, there was just an immediate offer to help."
A cultural shift in leveraging open source software
The ease of staying current on Chainguard's catalog has pushed the team toward a more disciplined update cadence overall: rather than deploying a tool and leaving it alone indefinitely, they're now more consistently evaluating upgrade paths, which Jose credits with keeping the team honest about their security posture as CIRRUS continues to scale.
"In almost every case, you're just dropping and replacing," Jose said. "So why wouldn't you? You're going to save yourself CVEs, and you're going to get a security person off your back, and that's hard to do."