A software company operates a critical microservices application on AWS Fargate. They need to ensure that container images used in production are free from known vulnerabilities and meet security standards before deployment. The process must be automated as part of their CI/CD pipeline. Which solution provides a secure and automated way to achieve this?
- AManually download container images from Docker Hub, scan them with an open-source tool on a developer's machine, and then upload them to Amazon ECR.
- BUse AWS CodeBuild to build container images and push them directly to Amazon ECR without any scanning, relying solely on runtime protection by AWS Fargate.
- CImplement a custom script in the CI/CD pipeline that pulls images from ECR, runs a third-party vulnerability scanner on an EC2 instance, and then manually approves or rejects the deployment.
- DConfigure Amazon ECR to automatically scan container images upon push using Amazon Inspector. Integrate this with the CI/CD pipeline to block deployments of images with critical vulnerabilities.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure Amazon ECR to automatically scan container images upon push using Amazon Inspector. Integrate this with the CI/CD pipeline to block deployments of images with critical vulnerabilities.
Amazon ECR's integration with Amazon Inspector provides automated vulnerability scanning of container images upon push. This can be integrated into a CI/CD pipeline to enforce security policies, such as blocking deployments of images with critical vulnerabilities, ensuring a secure container supply chain.
Why the other options are wrong
- A. Manual processes are error-prone, not scalable, and introduce significant security risks by relying on local scans and potentially untrusted sources.
- B. Deploying images without scanning is a significant security risk, as it allows vulnerable software into production. Fargate provides runtime isolation but does not prevent vulnerabilities within the container image itself.
- C. While using a third-party scanner is possible, a custom script and manual approval add operational overhead and are less integrated and automated than a managed service like ECR with Inspector.
Secure Container Image Pipeline
A set of automated processes and tools within a CI/CD pipeline designed to build, scan for vulnerabilities, and store container images securely, ensuring that only approved and secure images are deployed to production environments.
- Involves building images from trusted base images.
- Includes automated vulnerability scanning (e.g., Amazon ECR with Inspector).
- Enforces security policies to block vulnerable images.
- Stores images in a secure, private registry (Amazon ECR).
Memory trick: ECR + Inspector is like a 'security checkpoint' for container images before they board the 'production train'.