CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security engineer is tasked with hardening a new Kubernetes cluster. The organization requires that all container images deployed to the cluster must originate from an approved, scanned registry and be cryptographically signed by an authorized party. Which Kubernetes admission controller is BEST suited to enforce this policy?
- APodSecurityAdmission
- BLimitRanger
- CImagePolicyWebhook
- DNodeRestriction
Show answer & explanationAnswer & explanation
Correct answer: C. ImagePolicyWebhook
ImagePolicyWebhook is a Kubernetes admission controller that allows an external webhook service to validate or mutate image pull requests. This enables the enforcement of policies like requiring images from approved registries and verifying cryptographic signatures before a container is allowed to run, directly addressing the scenario's requirements.
Why the other options are wrong
- A. PodSecurityAdmission enforces security standards on Pods, focusing on runtime security context, not image origin or signing.
- B. LimitRanger enforces resource limits (CPU, memory) on Pods, not image security policies.
- D. NodeRestriction limits Kubelet access to API resources, primarily for multi-tenancy, and does not relate to image policy enforcement.
ImagePolicyWebhook
A Kubernetes admission controller that sends image pull requests to an external webhook service for validation or mutation based on defined policies.
- Enforces policies on container image usage
- Can validate image origin, registry, and cryptographic signatures
- Integrates with external policy engines
Memory trick: ImagePolicyWebhook: The bouncer for your cluster's images, checking IDs and signatures.