Cisco today announced a new framework for signing and validating serverless functions. The networking giant's Head of Open Source Stephen Augustus told SDxCentral this launch is significant because it fills a crucial gap in cloud-native software supply chain security.

"The idea behind FunctionClarity is that we want to provide that signing and validation functionality for serverless functions, because if you're attempting to secure a software supply chain and not considering all of the components of it, then you're not really doing what you set out to do," Augustus told SDxCentral.

The newly launched FunctionClarity tool falls under the networking giant's OpenClarity umbrella. This builds on Cisco's APIClarity and KubeClarity open source tools meant to provide advanced observability for APIs and detection and management of software bill of materials (SBOM) and vulnerabilities in container images and filesystems.

"There's this little dark space somewhere in the corner where serverless functions have gotten pretty popular. And every go-to cloud provider has some implementation of that, and then you've also got open source projects like Knative that leverage the same ideas so you can build out your own platform using serverless functions. And we're thinking hey, there's a gap there," Augustus said.

"It's still early days with FunctionClarity, but the fact that it addresses this gap that just seems to not have been addressed yet – I think it's rare to see that," he touted.

Security Vs. Convenience

Serverless computing, while often utopianized by developers, paints a different story from an operations perspective. Augustus admitted "hearing 'serverless' in general, like, freaks me out," citing his background in roles like corporate IT, DevOps, and production engineering where his responsibility was to prevent developers from arbitrarily executing code.

In serverless environments, code is still being deployed, and it still needs to be maintained from an ops point of view. "I don't think the dream of serverless has ever realized for that kind of persona," he said. "But for the developers, it's this really powerful concept."

"You have to meet them at the 'wow, this would be really great to get into a platform, but we still have to be able to protect it the same way that we would do if we were working in a more traditional environment,'" he explained, referencing the inverse relationship between security and convenience.

As the security controls ramp up, the convenience for everyone involved often goes down. "And part of that is because people have taken to bolting security onto the solution as opposed to building security as part of the solution," Augustus said. "The goal with something like FunctionClarity is we want to meet you where you are. We want to make sure that this process is just as safe and useful to developers as any other process in any other environment would be."

In terms of the new tool's initial users, Augustus expects FunctionClarity will resonate with those already using serverless functions. And, "it's going to lower some of the risk factors for people who are looking to get involved. So I think it's going to it's going to play to both audiences," he added.