Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium
A development team is preparing to deploy a new critical microservice to a production Kubernetes cluster. They are concerned about potential supply chain attacks, specifically the risk of compromised container images. Which security measure should they prioritize to ensure that only trusted and verified container images are deployed?
- AConfiguring image signing and verification in their CI/CD pipeline and admission controllers.
- BEnabling Pod Security Admission (PSA) with a 'baseline' policy for all namespaces.
- CImplementing robust network policies to restrict outbound traffic from Pods.
- DRegularly scanning running containers for vulnerabilities using a runtime security tool.
Show answer & explanationAnswer & explanation
Correct answer: A. Configuring image signing and verification in their CI/CD pipeline and admission controllers.
Image signing and verification directly address the supply chain risk of compromised container images. By signing images at build time and verifying those signatures during deployment (via admission controllers), organizations can ensure only trusted and unaltered images are run in their clusters.
Why the other options are wrong
- B. PSA 'baseline' policy enforces basic Pod security standards but doesn't specifically verify the origin or integrity of container images.
- C. Network policies address network-based attacks but do not prevent the deployment of compromised images.
- D. Runtime scanning detects vulnerabilities in running containers but is a reactive measure after a potentially compromised image has already been deployed.
Image Signing & Verification
A supply chain security practice where container images are cryptographically signed by their creators and these signatures are verified before the images are allowed to run in a Kubernetes cluster.
- Ensures image authenticity and integrity.
- Prevents deployment of tampered or unauthorized images.
- Typically integrated with CI/CD and admission controllers.
Memory trick: Sign your images to trust their journey to production.