A software company operates a critical microservices application on AWS Fargate. They need to ensure that container images deployed to Fargate are scanned for vulnerabilities before deployment and that only approved images are allowed to run. Which AWS services should be integrated to establish a secure container image supply chain?
- AAmazon ECR with image scanning, AWS CodePipeline for build/deploy, and AWS KMS for encryption.
- BAmazon ECR with image scanning, AWS CodeBuild for building images, and AWS Systems Manager Parameter Store for configuration.
- CAmazon ECR with lifecycle policies and AWS Secrets Manager.
- DAmazon ECR with image scanning, AWS CodePipeline for CI/CD, and AWS Fargate's task definition enforcement.
Show answer & explanationAnswer & explanation
Correct answer: D. Amazon ECR with image scanning, AWS CodePipeline for CI/CD, and AWS Fargate's task definition enforcement.
Amazon ECR's image scanning identifies vulnerabilities. Integrating this with AWS CodePipeline allows for automated build, scan, and deployment workflows. Crucially, CodePipeline can be configured to halt deployment if vulnerabilities are found. AWS Fargate's task definitions implicitly enforce the use of specific, approved images from ECR, ensuring only scanned and 'approved' images are run. This creates a secure container image supply chain.
Why the other options are wrong
- A. While ECR image scanning and CodePipeline are good, AWS KMS is for encryption, not directly for enforcing approved images in a supply chain.
- B. CodeBuild builds images, and Parameter Store manages configuration, but this option lacks the enforcement mechanism to prevent unapproved images from being deployed to Fargate.
- C. Lifecycle policies manage image retention, and Secrets Manager stores secrets; neither directly addresses vulnerability scanning or approved image enforcement.
Secure Container Supply Chain
A process flow that integrates container image scanning, automated build and deployment pipelines, and runtime enforcement to ensure only secure and approved container images are deployed.
- ECR image scanning for vulnerability detection.
- CodePipeline for automated CI/CD with gates.
- Fargate task definitions enforce approved images.
Memory trick: ECR Scan, CodePipeline Plan, Fargate Run!