Profile
Matt Moore ✦ Chainguard co-founder and CTO ✦ From container tools to a continuously rebuilt software factory

People / Software infrastructure

Matt Moore and the Art of Fixing the Defaults

A brisket photo became a startup text. Years of building container tools had prepared Matt Moore for a larger argument: the safest software should be the easiest software to use.

For a while, Dan Lorenc knew what to expect when he checked in on Matt Moore: a photograph of brisket. Moore had stepped away from big-company work, and the backyard smoker had apparently found an attentive operator. The running joke was that he cared more about bark and smoke rings than another engineering job. Then Lorenc asked again. Moore’s reply was different. He was ready to get back to work, he said, and they should start their own thing. In 2021, that thing became Chainguard.

Founding stories tend to acquire a polished inevitability in retrospect. This one has the good sense to include lunch. Yet the idea behind the company had been cooking much longer than a brisket. Moore had spent years building the tools and services that move software from a developer’s machine into production. The question underneath that work was deceptively ordinary: what happens when everyone trusts the package because it arrived by the usual route?

Today Moore is Chainguard’s co-founder and chief technology officer. The company builds open source artifacts from source, signs them, and keeps rebuilding them as software changes. It sells a way to use open source without making every customer repeat the same maintenance work. That description is technical because the work is technical. The human part is simpler. Moore wants engineers to begin from a safer place before the first alarm goes off.

Before the factory, the tools

Moore studied computer science at Carnegie Mellon University, graduating in 2005 with university honors. He started his career on compiler optimization at Microsoft. Compilers are an early lesson in consequences: a decision made deep in the machinery can alter the behavior of an enormous amount of software without its users ever seeing the decision. His later work would sit in a different part of the stack, but it carried the same taste for the places where small design choices spread widely.

At Google, he moved into developer tools and containers. He led the creation of Google Container Registry, the service that stored container images for developers building on Google Cloud. From there he helped shape an unusually long list of open source projects: distroless, kaniko, Jib, ko, and the Go container registry library used elsewhere in the ecosystem. With fellow future co-founder Ville Aikas, he started Knative, a project for running serverless workloads on Kubernetes, and helped launch its Tekton spin-off.

The names may read like a small alphabet storm to anyone outside cloud infrastructure. Their shared purpose is more legible. They make software easier to build, package, deliver, or run. Every one of those steps is also a chance to import something unwanted: a stale dependency, a surprising permission, a package nobody can account for. Moore’s career put him near the junction where convenience and trust meet. Convenience usually wins the first encounter. He wanted to change the terms.

Distroless offered a particularly sharp version of the argument. A conventional container image often includes a shell and package manager, useful to a person investigating the environment but unnecessary for the application that runs there. Remove what the application does not need, and there is less to maintain and less for an intruder to use. Moore later recalled giving an early talk on the idea and watching people look at him as though he were an alien. Developers loved their Dockerfiles. Why would they give up the familiar pieces?

Years later he heard a conference speaker use “distroless” without stopping to define it. The former oddity had become part of the vocabulary. Moore laughed at the distance between the two rooms. There is a quiet sort of influence in making an idea ordinary enough that nobody pauses over it.

“The number itself is less interesting than the system that produced it.”Matt Moore, on Chainguard’s build-manifest milestone

A company built around the boring part

Chainguard’s launch in October 2021 brought Moore together with Lorenc, Aikas, Kim Lewandowski, and Scott Nichols. The company’s premise was direct: software supply chains should be secure by default. That meant paying attention to the work between source code and the thing a customer downloads. A signed artifact can show that it came through a known process. A software bill of materials can say what is inside. A minimal image can carry less that does not belong. None of those properties is theatrical. Together, they change what a developer can know.

Moore had called his earlier career “serial entrepreneurship inside of big companies.” At Microsoft and Google he could start projects that reached substantial audiences, but a company of his own would expose him to questions the engineering chart did not answer. In a 2026 interview, he described learning the go-to-market side: sales, marketing, and the work of helping customers before and after a purchase. It is an adjustment many technical founders discover only after the product exists. Being right about a problem does not automatically explain it to the person holding a budget.

The company’s early pitch also had to contend with a familiar security fatigue. Developers had heard many instructions to scan, patch, and document more. Moore’s point was that much of the burden could be handled before the software arrived. Chainguard began with container images, then expanded its catalog into libraries and other artifacts. A customer could spend less time maintaining the same open source ingredients as every other customer. That is a commercial proposition, but it is also a view of waste: thousands of teams should not each have to solve the identical patching problem alone.

1Password Zero-Shot Learning graphic featuring Matt Moore and a Build from source episode
Matt Moore in a 2026 conversation with 1Password about build identity and open source trust.

What changes after the download

A secure image on the day it is downloaded is only a snapshot. Tomorrow a library changes, a vulnerability is disclosed, or a new version of a language runtime appears. The work begins again. Moore has become increasingly interested in the machinery that handles this repetition, which may be the least glamorous and most consequential part of his job.

Chainguard’s first software factory automated much of the building, signing, and shipping. As the catalog grew, Moore wrote, the system became a thicket of event notifications and brittle queues. Failures could collide or require a person to finish the job. The team’s phrase for the resulting maintenance treadmill was the “CVE doom loop.” The problem was not a lack of effort. The architecture asked humans to keep rescuing a process designed to run continuously.

In January 2026, Moore and colleagues introduced Factory 2.0, powered by an open source framework called DriftlessAF. It uses reconciliation: compare what should exist with what actually exists, then keep working toward the desired state. A newly reported vulnerability, an upstream release, or a changed build rule can put an item into the queue. Bots handle tasks repeatedly; a failed step can be retried because the destination remains clear. AI handles some judgment calls that fixed automation struggles with, while the build process still needs verifiable results.

The mechanism sounds abstract until the scale becomes visible. In September 2026, Moore reported that Chainguard had passed one billion container build manifests, up from 500 million six months earlier. It also had more than 3,000 unique container images and 675,000 image versions in its catalog. A manifest can represent a new release, a rebuild following a patch, an architecture variant, or another verifiable artifact. One billion is an arresting number. Moore was more interested in whether the system could keep the catalog fresh after each change.

1B+Build manifests
3,000+Unique images
675,000Image versions

He does not describe automation as permission to stop thinking. The framework gives engineers a different set of tasks: review proposed changes, improve tests, and refine the system’s rules. In Moore’s account, AI earns a place where it can deal with messy inputs that ordinary scripts cannot, such as interpreting an unexpected component in a minor release. The output still has to survive structured checks. This is an engineer’s version of optimism: enthusiasm, followed closely by a test.

Trust has a shelf life

Moore’s recent conversations about AI bring him back to identity. If a build system can publish an artifact, what proves that the build was the one intended? What could a stolen credential allow someone else to publish? Speaking with 1Password in 2026, he pressed the case for short-lived credentials and access limited to the specific task. A credential that lives indefinitely gives an attacker time and opportunity; one that expires quickly and can do little has a narrower reach.

This is the same argument he has made from several angles over the years. Minimal containers remove unnecessary tools. Signed builds let a consumer verify provenance. Continuous rebuilding reduces the gap between an upstream change and an updated artifact. Scoped credentials limit what a compromised identity can do. Each measure covers a different moment in the life of software. None asks a busy developer to become a full-time security specialist before writing the next feature.

There is room for humor in a career spent on rather solemn nouns. Moore’s GitHub biography says “tinkering.” He has joked that he can talk all day if someone gets him started. At Chainguard’s 2025 Assemble event, he remembered the early bafflement over distroless with evident amusement. The details matter because they keep the work from becoming a morality play about negligent developers and vigilant security teams. People use the tools placed in front of them. Better tools can make better behavior feel natural.

That thought also explains why his return to Carnegie Mellon in 2025 had more than a ceremonial quality. Chainguard announced work with the university’s CyLab Venture Network on open source security, supply chain transparency, and secure container infrastructure. Moore called it a full-circle connection to the place that helped shape his career. The company would take part in discussions and mentoring as well as technical collaboration. A field built on shared code also depends on shared knowledge.

A text that interrupted a brisket conversation became a company. Five years later, Moore’s work is much larger than the founding anecdote, but the two still fit. He left established institutions, then built another institution around a recurring irritation: too much software arrives with trust assumed and maintenance deferred. His answer has been to move the hard work earlier, make its evidence visible, and repeat it as often as the world changes. The ambition is modest in wording and enormous in practice. Someday, a developer may download an artifact that is current, minimal, and verifiable, and find nothing unusual about it.