Professional Cloud Security EngineerEnsuring complianceEasy
A global software company is deploying a new application to Google Kubernetes Engine (GKE). They need to ensure that all container images deployed to their GKE clusters are signed and verified against a trusted authority before they are allowed to run. This is a critical security requirement to prevent unauthorized or tampered images from being executed. Which Google Cloud service is designed to enforce this policy?
- ABinary Authorization
- BCloud Build
- CContainer Registry
- DArtifact Registry
Show answer & explanationAnswer & explanation
Correct answer: A. Binary Authorization
Binary Authorization enforces deploy-time security policies by requiring images to be signed by trusted authorities and verified before deployment. This directly addresses the requirement to ensure only signed and verified container images run on GKE.
Why the other options are wrong
- B. Cloud Build is a CI/CD service for building artifacts, not for enforcing runtime deployment policies.
- C. Container Registry stores Docker images but does not enforce deployment policies based on signatures.
- D. Artifact Registry stores various artifacts, including container images, but does not enforce deploy-time authorization.
Binary Authorization
A deploy-time security control that ensures only trusted container images are deployed to Google Kubernetes Engine (GKE), Cloud Run, and App Engine.
- Enforces policies based on image signatures.
- Prevents deployment of unauthorized or tampered images.
- Integrates with Cloud Key Management Service (KMS) for signing keys.
Memory trick: Binary Auth: Only Signed Ships Set Sail.