CompTIA SecurityX (CAS-005)Security EngineeringMedium
A security engineer is tasked with hardening a new Kubernetes cluster. The organization requires that all container images deployed to production namespaces must originate from an approved, trusted registry and be cryptographically signed by the internal CI/CD pipeline. Which Kubernetes admission controller should the engineer configure to enforce this policy?
- AImagePolicyWebhook
- BPodSecurityPolicy (deprecated)
- CLimitRange
- DResourceQuota
Show answer & explanationAnswer & explanation
Correct answer: A. ImagePolicyWebhook
ImagePolicyWebhook is a Kubernetes admission controller that allows an external webhook service to validate or mutate image deployment requests. It is the appropriate tool for enforcing policies like requiring images from trusted registries and cryptographic signatures, as it can inspect the image reference and consult an external policy engine.
Why the other options are wrong
- B. PodSecurityPolicy is deprecated in favor of Pod Security Admission and does not directly address image signing from external registries.
- C. LimitRange sets resource limits for pods and containers within a namespace, not image policies.
- D. ResourceQuota limits resource consumption per namespace, which is unrelated to image provenance.
ImagePolicyWebhook
A Kubernetes admission controller that intercepts requests to create or update Pods and sends image-related information to an external webhook for policy evaluation, typically used to enforce image provenance and signing.
- Enforces policies on container images.
- Uses an external webhook for validation.
- Can require images from trusted registries or with signatures.
Memory trick: The IMAGE POLICE WEBHOOK will check your container's papers.