Rise8 trusts Chainguard to secure the platform behind its DoD software pipeline

The challenge

The Rise8 team operates a vetting pipeline that evaluates third-party containerized software for delivery to a Palantir environment — essentially a secure on-ramp for Department of Defense (DoD), also referred to as the Department of War (DoW), software. That pipeline has to meet the same standard it enforces.

The platform is assembled from a stack of open source and licensed tools: GitLab, Grafana, Keycloak, Mimir, and more. Every one of the container images in the platform has to meet federal security standards before Rise8 can obtain an Authorization to Operate (ATO), the government approval that determines whether the platform can go live at all.

And with a team structured to build the platform, hardening it themselves wasn't a realistic path. As Dan Sanker, Platform Engineer at Rise8, noted from experience, remediating images like Grafana meant dedicated headcount and weeks to months of work per tool, effort the current contract simply wasn't scoped for.

The solution

From the inception of the U.S. Space Force project, Rise8 turned to Chainguard Containers for its core observability and platform tooling.

Rather than treating image security as a remediation task, the team built the platform architecture around Chainguard as a trusted source, pulling images directly from the Chainguard Repository for core tooling and building the update pipeline around Chainguard's delivery cadence. Onboarding the full team took just days, and adding or removing team members has remained equally seamless.

When a new image is released, Rise8's own scanning pipeline runs a comparison against its current image and updates accordingly, creating a two-layer security posture: Chainguard attests to the image, and Rise8 independently verifies it.

The results

Reallocation of engineering time

With Chainguard handling image security for the project’s core tooling, the team has been able to stay focused on what the contract is actually scoped for: building the platform. CVE remediation simply no longer appears in planning cycles. As Steven Souto, Senior Software Engineer at Rise8, put it, "We don't have to do that work, and instead we can just focus on the features that our service offers."

CVE remediation is not an area we need to focus on because we know that with Chainguard, in a matter of hours to days, there will be an update that identifies and remediates the issue.
DAN SANKER, PLATFORM ENGINEER, RISE8

Reduced security engineering burden

The impact is perhaps most visible in the day-to-day work of the team’s security engineers. Without a hardened image, every tool version bump triggers a cycle of suppression management, risk conversations, and documentation overhead. When a Chainguard image is in place, that cycle disappears. The Rise8 team has made Chainguard provenance an explicit part of the architecture documentation presented to their Authorizing Official (AO).

A more defensible path to ATO

Obtaining an ATO requires Rise8 to demonstrate to a government AO that its platform is operating safely. Chainguard changes the nature of that conversation. Rather than walking an AO through an in-house hardening process and fielding the scrutiny that comes with it, Rise8 can point to a trusted third party that attests to vulnerability-free images, backed by Rise8's own independent verification layer. The alternative has a credibility problem: an AO would question whether a pipeline can objectively validate the very image it runs on. That two-layer posture, sourcing from Chainguard then independently verifying, is cleaner, more defensible, and puts less on Rise8's plate to prove.

Being able to say that the majority of our services have a whole Chainguard team contracted to resolve those vulnerabilities is a major win.
STEVEN SOUTO, SENIOR SOFTWARE ENGINEER, RISE8

Building long-term credibility with government customers

For Rise8, the ATO isn't just a compliance checkbox; it's the foundation of a longer relationship with government customers. Every time the team delivers a clean, low-CVE package through the vetting pipeline, it builds confidence with the approval chains that determine what software reaches production.

As Dan explained, “Our goal is to build the relationship and confidence in the cybersecurity approval chains. If we continue to show up with secure projects and secure images, we build that confidence. They know that if our team delivers a project, there’s a certain level of professionalism. Having low-to-no CVEs walking in the door with Chainguard provides that polish that we need.”

share this article

Rise8 trusts Chainguard to secure the platform behind its DoD software pipeline

Execute commandCG System prompt

$ chainguard learn --more

Contact us