Skip to content

Lesson 1: Container Security & Supply Chain

🧠 The Concept (Explain Like I'm 5)

If you buy an apple from a stranger on the street, you don't know where it came from or if it's safe (Untrusted Docker Image). If you buy an apple from a certified farm with a wax seal of approval, you know it's safe (Signed & Scanned Image). Trivy checks the apple for poison (vulnerabilities). Cosign puts the wax seal on it (cryptographic signing).


🏒 The Enterprise Context

  • Software Supply Chain Attacks: Attackers (like in the SolarWinds breach) don't hack the production server directly; they inject malware into the build pipeline.
  • SLSA (Supply-chain Levels for Software Artifacts): A security framework to ensure code hasn't been tampered with between the Git commit and the Kubernetes cluster.
  • Kyverno / OPA Gatekeeper: A Kubernetes admission controller that checks for the "wax seal" before allowing the container to run.

πŸ—ΊοΈ Visual Architecture: Secure Supply Chain

flowchart TD
    Git["Git Repository"] --> CI["CI Pipeline (Build)"]
    CI --> Img["Docker Image"]
    Img --> Trivy{"Trivy Vulnerability Scan"}

    Trivy -->|CVEs Found| Fail["❌ Block Build"]
    Trivy -->|Clean| Cosign["Cosign (Cryptographic Sign)"]

    Cosign --> Registry[("Container Registry<br/>(ECR / Harbor)")]

    Registry --> K8s["Kubernetes Cluster"]
    K8s --> Kyverno{"Kyverno Admission Controller"}

    Kyverno -->|Signature Invalid| BlockDeploy["❌ Block Pod"]
    Kyverno -->|Signature Valid| Run["βœ… Run Pod"]