Container Scanning: Trivy, Grype. Differentiating between OS-level CVEs and application-dependency CVEs.
SBOMs: Generating Software Bill of Materials using Syft (SPDX vs CycloneDX formats).
Cryptographic Signing: Sigstore/Cosign. Keyless signing via OIDC.
3. Kubernetes Admission Control
Dynamic Admission Webhooks: Mutating vs Validating webhooks.
Kyverno / OPA Gatekeeper: Writing policies to enforce security standards at the Kubernetes API level before pods are scheduled.
π οΈ Job-Essential Exercises
The Vulnerable Build CI Pipeline:
Write a GitHub Action that builds a Docker image. Add a step to run Trivy. Introduce an outdated dependency (e.g., an old Log4j or Express.js version). Ensure Trivy breaks the pipeline.
The Cryptographic Supply Chain:
Once the image passes Trivy, add a GitHub Action step to sign the Docker image using Cosign. Push the signed image to Amazon ECR or GitHub Container Registry.
The Admission Shield:
Install Kyverno on a Kubernetes cluster. Write a ClusterPolicy that blocks any pod deployment if the container image does not possess a valid Cosign signature from your public key. Try to kubectl apply an unsigned NGINX image and watch the API reject it.