If anyone can run any image, your cluster inherits the internet’s vulnerabilities. Start with approved base images, frequent rebuilds, and scanners that fail on actionable severity.
Produce SBOMs, sign images, and verify signatures at admission. Keep registries private and credentials short-lived.
Separate build and runtime identities. A compromised runner should not become permanent cluster admin.
Supply chain controls are boring when they work—and career-defining when they do not.
Rebuild bases on a schedule even when application code is quiet.
Restrict who can push to production registries and monitor unexpected digests.
Include supply-chain steps in incident response: how to revoke a bad image across clusters fast.
Key takeaways
- Approved bases, scanning, SBOMs, and admission verification belong together.
- Sign images and verify signatures before they run.
- Keep build identity separate from cluster admin identity.
FAQ
Do image scans alone make us safe?
No. Scans without rebuild cadence, admission controls, and runtime policies leave known-bad images runnable.
What should fail a deploy?
Critical vulnerabilities with known fixes on your owned layers, unsigned images, and bases outside the approved list—tuned so teams can remediate quickly.