Professional Cloud Security EngineerEnsuring complianceMedium
A software development company uses Google Kubernetes Engine (GKE) for deploying its applications. They need to ensure that only container images from their trusted Continuous Integration/Continuous Delivery (CI/CD) pipeline are deployed to production GKE clusters. Images signed by unauthorized keys or from untrusted registries should be blocked. Which Google Cloud service should they implement?
- AArtifact Registry
- BContainer Registry
- CBinary Authorization
- DSecurity Command Center
Show answer & explanationAnswer & explanation
Correct answer: C. Binary Authorization
Binary Authorization enforces deployment policies on GKE clusters by requiring images to be signed by trusted authorities (attestors) before they can be deployed. It blocks deployments of non-compliant images.
Why the other options are wrong
- A. Artifact Registry is a universal package manager that stores various artifacts, including container images, but doesn't enforce deployment policies.
- B. Container Registry stores Docker images, but doesn't enforce deployment policies.
- D. Security Command Center provides security insights and vulnerability management, but doesn't prevent non-compliant deployments in real-time.
Binary Authorization
Binary Authorization is a Google Cloud service that enforces deployment policies on Google Kubernetes Engine (GKE) clusters, ensuring only trusted and authorized container images are deployed.
- Requires images to be signed by approved attestors.
- Blocks deployment of unauthorized or unsigned images.
- Integrates with CI/CD pipelines for automated image signing.
Memory trick: Binary Authorization is like a 'bouncer' for your GKE, only letting in signed guests.