Golden paths: how to ship securely without slowing developers

The secure path and the easy path should be the same path.

Ralph McTeggart (Principal Engineer), Alex Franzmann (Customer Onboarding Team Lead), and Claire McDyre (Product Manager) at Cloudsmith lay out how platform teams can deliver supply chain security as a capability rather than a checklist. The argument runs from first principles: make a private registry the default, automate policy enforcement at the global level, and extend that same logic to compliance – so SBOM generation happens in the pipeline, not as a developer's manual task.

Areas they cover:

  • Why the golden path approach works: security controls developers can't easily bypass don't need to be enforced manually
  • How a pre-configured private registry with upstream proxies covers all ecosystems without adding developer overhead
  • Why teams defining their own security controls independently creates inconsistency and risk – and how global policy automation prevents it
  • How to make SBOM generation part of your build pipeline via templates so it happens automatically rather than on request
  • Why making SBOM results visible to developers drives ownership and supports self-service compliance

0:00 - Security as the default path

0:57 - What a golden path looks like in practice

1:31 - Pre-configured registries and automatic policy enforcement

2:03 - Why developer burden kills compliance adoption

2:26 - Automating SBOM generation in the build pipeline

2:58 - Self-service compliance through transparency

This video covers platform engineering, golden paths, software supply chain security, SBOM generation, developer experience, dependency management, and self-service compliance for platform teams, engineering managers, and developer experience leads.

See how Cloudsmith can help develop your own golden paths. Book a demo: https://cloudsmith.com/book-a-demo

Subscribe for more on software supply chain security, platform engineering, and artifact management.

#PlatformEngineering #DevSecOps #Cloudsmith #SBOM