Why Kubernetes-Native CI/CD Matters
Traditional CI/CD systems (Jenkins, CircleCI, GitHub Actions) run outside Kubernetes. Tekton runs inside Kubernetes as custom resources — pipelines, tasks, and runs are Kubernetes objects managed by the same RBAC, networking, and audit infrastructure as your applications. For platform teams building internal developer platforms, this means one less system to manage and one more thing that benefits from your existing Kubernetes governance.
Tekton for Compliance
Supply Chain Security (SLSA)
Tekton Chains provides SLSA (Supply chain Levels for Software Artifacts) provenance:
- Build provenance: Automatically generates signed attestations for every build — who built what, from which source, using which pipeline
- Hermetic builds: Isolated build environments that can't access external networks during build (preventing supply chain attacks)
- Signed artifacts: Container images automatically signed with cosign upon build completion
- SLSA Level 3: Tekton + Chains can achieve SLSA Level 3 compliance out of the box
CRA compliance: The Cyber Resilience Act requires supply chain transparency. SLSA provenance provides verifiable evidence of how every artifact was built.
Audit Trail & Governance
- Kubernetes audit log: Every pipeline run is a Kubernetes resource — creation, modification, and deletion logged by the K8s API server
- RBAC: Control who can create, run, or view pipelines using standard Kubernetes RBAC
- Namespace isolation: Pipelines run in isolated namespaces with scoped permissions
- Results and artifacts: Pipeline results stored in Kubernetes or external storage with full traceability
Tekton vs Jenkins vs GitHub Actions
| Aspect | Tekton | Jenkins | GitHub Actions |
|---|---|---|---|
| Runs on | Kubernetes (native CRDs) | JVM server (+K8s agents optional) | GitHub cloud (or self-hosted runners) |
| Supply chain | SLSA via Tekton Chains | Plugins (manual) | Artifact attestations (beta) |
| Scaling | Kubernetes-native (infinite) | Agent-based (manual scaling) | Concurrent job limits |
| Data sovereignty | Full control (self-hosted) | Full control (self-hosted) | GitHub-hosted (US) or self-hosted |
| Learning curve | Moderate (K8s knowledge required) | Low (widely known) | Low (YAML workflows) |
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Getting Started
- Install Tekton Pipelines in your Kubernetes cluster (single kubectl apply)
- Install Tekton Chains for automatic build provenance and signing
- Create your first Pipeline — build, test, scan, deploy workflow
- Integrate with ArgoCD — Tekton builds images, ArgoCD deploys from GitOps repo
- Set up Tekton Dashboard for pipeline visibility and debugging
Luca Berton