-

CloudBees Releases Hardened CloudBees CI to Enable Secure, DoD-Compliant Software Delivery Practices

New version of CloudBees CI solution meets stringent United States Department of Defense standards 

SAN JOSE, Calif.--(BUSINESS WIRE)--CloudBees, Inc., the enterprise software delivery company, today unveiled a hardened version of CloudBees CI, the industry-leading continuous integration (CI) solution. The new version meets the United States Department of Defense (DoD) specifications for security, one of the most demanding security certifications in the world. The new release of CloudBees CI (formerly known as CloudBees Core) is available immediately and enables DoD and civilian agencies of the U.S. federal government, as well as enterprises in private industry, to drive more value through their software delivery pipelines while lowering security risk.

Federal government agencies facing time-to-mission pressures are trying to automate pipelines to accelerate the building of new applications and add urgently needed functionality to existing applications. But they’re constrained by Information Assurance guidelines requiring CI tools to pass advanced security certifications. The hardened version of CloudBees CI provides a container that has achieved a Certificate to Field (CtF) from the U.S. Air Force Platform One team. Platform One is the official DevSecOps Enterprise Services team for the DoD.

A CtF is a formal certification given by the U.S. Air Force Platform One team. Software containers that receive a CtF can be used to deploy a platform within a specific environment that has received an Authority to Operate (ATO). An ATO certification means that a platform meets security standards as set forth by DISA STIG and NIST RMF guidelines. Platform One provides platforms that are already accredited and can only use containerized software with an approved CtF.

“With the CtF, CloudBees CI can be readily used by DoD agencies, as well as civilian agencies and federal system integrators (FSIs),” said Michael Wright, director, federal sector, at CloudBees. “It provides all the benefits of CI in a Jenkins environment, and it meets rigorous government standards for security and compliance.”

CloudBees CI is built on Jenkins, the most widely-used automation server in the world. CloudBees CI provides flexible, governed CI and can be hosted on-premise, in the public cloud or in a hybrid environment. It enables teams to centrally manage software development tools, optimize software delivery velocity, maximize developer team efficiency and enforce global compliance policies.

“The Department of Defense has made software delivery a top priority. DevSecOps vendors, such as CloudBees, getting authorized to DoD standards supports the mission of the Department of Defense enterprise DevSecOps initiative,” said Nicolas Chaillan, Air Force chief software officer and co-lead for the DoD Enterprise DevSecOps Initiative. “The goal of this initiative is to enable DoD programs in their transition to agile and DevSecOps. We want to establish force-wide DevSecOps capabilities and best practices, as well as foster continuous ATO processes and faster, more streamlined technology adoption.”

CloudBees CI provides a hardened Docker container image which is placed in the Department of Defense Centralized Artifact Repository (DCAR), the storage repository maintained by the DoD. Teams from any DoD or civilian agency can access and simply pull the hardened Docker container image out of DCAR. The solution has been engineered to minimize the use of any libraries or components that have known security vulnerabilities. For example, if a team uses a library to execute http communication between a CloudBees CI master and agent, the functionality within CloudBees CI ensures secure ports and protocols are used at both ends.

The new hardened version of CloudBees CI can not only help agencies transform to secure DevSecOps processes – but also enterprises operating in highly regulated industries or those simply wanting heightened security capabilities.

Additional Resources

Listen to a DevOps Radio podcast with Nicolas Chaillan, Air Force Chief Software Officer

Try CloudBees CI for free

Learn about CloudBees CI

Read the blog: Orchestrating DevSecOps: Security at Speed

Read the blog: How DevSecOps Helps the Federal Government Achieve Continuous ATO

Learn how CloudBees can help government agencies

About CloudBees

CloudBees, the enterprise software delivery company, provides the industry’s leading DevOps technology platform. CloudBees enables developers to focus on what they do best: Build stuff that matters, while providing peace of mind to management with powerful risk mitigation, compliance and governance tools. Used by 50% of the Fortune 100, CloudBees is helping thousands of companies harness the power of continuous everything and gets them on the fastest path from great idea, to great software, to amazing customer experiences, to being a business that changes lives.

Backed by Matrix Partners, Lightspeed Venture Partners, Verizon Ventures, Delta-v Capital, Golub Capital and Unusual Ventures, CloudBees was founded in 2010 by former JBoss CTO Sacha Labourey and an elite team of continuous integration, continuous delivery and DevOps professionals. Follow CloudBees on Twitter, Facebook and LinkedIn.

Contacts

Sydney Holmquist
PAN Communications
+1.407.734.7327
cloudbees@pancomm.com

CloudBees, Inc.


Release Versions

Contacts

Sydney Holmquist
PAN Communications
+1.407.734.7327
cloudbees@pancomm.com

More News From CloudBees, Inc.

CloudBees Integration with Argo Rollouts Enables Advanced Deployment Strategies to Kubernetes

SAN JOSE, Calif.--(BUSINESS WIRE)--CloudBees, the leading software delivery platform for enterprises, today announced the integration of CloudBees’ continuous delivery and release orchestration solution, CloudBees CD/RO, with Argo Rollouts. The integration will enhance customers' ability to deliver software faster, with higher quality, and at scale in cloud-native environments. This latest integration for CloudBees furthers its ability to support customers to deploy applications with confidence...

CloudBees Welcomes ThoughtSpot Chief Development Officer Sumeet Arora to Board of Directors

SAN JOSE, Calif.--(BUSINESS WIRE)--CloudBees, the leading software delivery platform for enterprises, today announced the appointment of Sumeet Arora, chief development officer at ThoughtSpot, the leader in AI-powered analytics, to its board of directors. With a background in engineering, product strategy, and security, Arora brings more than 25 years of leadership experience to the board of directors. “We are pleased to have Sumeet join the board at CloudBees. He will bring valuable experience...

CloudBees Names Marc Gemassmer as Chief Revenue Officer

SAN JOSE, Calif.--(BUSINESS WIRE)--CloudBees, the leading software delivery platform for enterprises, today named a new chief revenue officer (CRO), Marc Gemassmer. Gemassmer will lead the company’s global go-to-market and customer success efforts, partner and channel group, as well as the professional services organization. “With Marc’s experience and proven track record of building high-growth sales organizations at a global scale, he is the experienced partner we need to drive the company fo...
Back to Newsroom