Professional Cloud Security EngineerEnsuring complianceMedium

A software development company uses Google Kubernetes Engine (GKE) for deploying its applications. They need to ensure that only container images from their trusted Continuous Integration/Continuous Delivery (CI/CD) pipeline are deployed to production GKE clusters. Images signed by unauthorized keys or from untrusted registries should be blocked. Which Google Cloud service should they implement?

  1. AArtifact Registry
  2. BContainer Registry
  3. CBinary Authorization
  4. DSecurity Command Center
Show answer & explanation

Correct answer: C. Binary Authorization

Binary Authorization enforces deployment policies on GKE clusters by requiring images to be signed by trusted authorities (attestors) before they can be deployed. It blocks deployments of non-compliant images.

Why the other options are wrong

  • A. Artifact Registry is a universal package manager that stores various artifacts, including container images, but doesn't enforce deployment policies.
  • B. Container Registry stores Docker images, but doesn't enforce deployment policies.
  • D. Security Command Center provides security insights and vulnerability management, but doesn't prevent non-compliant deployments in real-time.

Binary Authorization

Binary Authorization is a Google Cloud service that enforces deployment policies on Google Kubernetes Engine (GKE) clusters, ensuring only trusted and authorized container images are deployed.

  • Requires images to be signed by approved attestors.
  • Blocks deployment of unauthorized or unsigned images.
  • Integrates with CI/CD pipelines for automated image signing.

Memory trick: Binary Authorization is like a 'bouncer' for your GKE, only letting in signed guests.

More Ensuring compliance questions