Lesson 1: Container Security & Supply Chain
π§ The Concept (Explain Like I'm 5)
If you buy an apple from a stranger on the street, you don't know where it came from or if it's safe (Untrusted Docker Image). If you buy an apple from a certified farm with a wax seal of approval, you know it's safe (Signed & Scanned Image). Trivy checks the apple for poison (vulnerabilities). Cosign puts the wax seal on it (cryptographic signing).
π’ The Enterprise Context
- Software Supply Chain Attacks: Attackers (like in the SolarWinds breach) don't hack the production server directly; they inject malware into the build pipeline.
- SLSA (Supply-chain Levels for Software Artifacts): A security framework to ensure code hasn't been tampered with between the Git commit and the Kubernetes cluster.
- Kyverno / OPA Gatekeeper: A Kubernetes admission controller that checks for the "wax seal" before allowing the container to run.
πΊοΈ Visual Architecture: Secure Supply Chain
flowchart TD
Git["Git Repository"] --> CI["CI Pipeline (Build)"]
CI --> Img["Docker Image"]
Img --> Trivy{"Trivy Vulnerability Scan"}
Trivy -->|CVEs Found| Fail["β Block Build"]
Trivy -->|Clean| Cosign["Cosign (Cryptographic Sign)"]
Cosign --> Registry[("Container Registry<br/>(ECR / Harbor)")]
Registry --> K8s["Kubernetes Cluster"]
K8s --> Kyverno{"Kyverno Admission Controller"}
Kyverno -->|Signature Invalid| BlockDeploy["β Block Pod"]
Kyverno -->|Signature Valid| Run["β
Run Pod"]