Memory hook: Know the contents, verify the origin, enforce before execution.
Must remember
Use minimal maintained base images, multi-stage builds and pinned reviewed digests. Remove unused packages and secrets; a smaller image reduces attack surface but does not prove safety. Distroless images can improve runtime minimalism while requiring a separate debugging strategy.
An SBOM inventories software components and versions. Vulnerability scanning compares them and other evidence to known issues; prioritize by exploitability, exposure and business impact. A signature binds an artifact to an identity under a trust policy; provenance describes its build origin/process. None alone proves the application has no malicious logic or unknown flaws.
Protect source review, build runners, dependency sources, registry credentials and promotion. Avoid rebuilding a different artifact for each environment; promote an immutable tested digest. Restrict permitted registries and use signature/attestation verification through an appropriate admission policy/tooling. A registry allow list says where an image came from, not whether its publisher or contents are trustworthy.
Static manifest analysis such as Kubesec or KubeLinter can detect risky configuration before deployment. Image scanning finds a different class of issues. Integrate checks into delivery and define exception ownership/expiry. Re-evaluate deployed images when new vulnerability information appears.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Understand packaged dependencies | SBOM plus validated inventory. |
| Verify artifact publisher/build evidence | Signature/provenance under a defined trust policy. |
| Block disallowed image sources | Admission enforcement, not only a written guideline. |
Traps
- Signed does not mean vulnerability-free.
- A scan at build time cannot know every vulnerability discovered later.
Active recall
1. What does an SBOM list?
Software components and versions in an artifact.
2. Digest versus tag?
Content identifier versus a potentially movable name.
3. Why scan manifests as well as images?
Deployment permissions/configuration can be unsafe even when image packages are patched.
4. Why protect build runners?
Compromised build infrastructure can produce malicious artifacts with apparently legitimate provenance.
5. What must an exception include?
Accountable approval, scope, compensating controls and review/expiry.