← CKS: Kubernetes security in production
11 / 11 · 60 MIN

Artifacts and incident timelines

Separate artifact identity, credential exposure and request outcomes in release analysis.

Read effective image state

A Pod created with an ordinary tag and omitted imagePullPolicy can receive IfNotPresent by default. Later changing the tag to latest does not automatically recalculate that field. Inspect the effective object and express intent in configuration. Always also does not imply downloading every byte again: runtime can reuse available content for the resolved digest. Record digest and policy in diagnosis. These distinctions help explain why an expectation based on a tag name does not match observed behavior during recovery.

Keep secrets out of build outputs

A secret mount temporarily provides a credential to a build instruction. That does not prevent the command from printing it or copying it into persistent output. In the fictional case, the token appears in shared CI logs even though the mount has ended. Response should address the credential, access to its copy and command correction, with appropriate evidence preservation. Do not copy the value into the incident ticket. Image vulnerability scanning answers another question and does not establish that a disclosed credential can no longer be used.

Interpret filters and provenance claims

A report changing from six findings to zero without an image change deserves comparison of used options. The ignore-unfixed filter can hide results lacking available fixes; it does not repair components. Also inspect severity source, distribution and package before comparing tools. In an attestation, verifying the approved builder’s signature establishes part of trust, but claims must still satisfy organizational policy. The technical manager should request evidence for each gate rather than accept one word, such as verified, as approval across every dimension.

Reconstruct requests from stages

An API request can produce several audit events. Group stages by auditID before counting attempts and consider outcome, principal, resource and interval. RequestReceived establishes receipt rather than success. A watch can have ResponseStarted while its response remains open. In the exercise, six lines, including export duplicates, belong to two requests: one patch ends with 200 and another with 403. The report should preserve that difference. Aggregated analysis can help management, but it should remain connected to original records for investigation and review.

Check coverage before concluding

The API process can remain healthy while its audit destination fails. Rising export errors require bounding the interval and seeking complementary sources instead of claiming complete coverage. Define who checks collection, delivery, retention and record access. If final events are missing, classify the outcome as unconfirmed in the available set. Keep investigation chronology separate from hypotheses still needing proof. In a management meeting, explain which operation is established, which remains uncertain and what evidence could resolve the uncertainty.

Close release with reproducible recovery

Connect digest, pull configuration, scan result with explicit options, evaluated attestation and absence of disclosure in the new build. Then confirm useful operation and auditing required by the service. If the incident involved a credential, recovery must cover that credential as well as the artifact. Include owners, stop criteria, approved alternatives and query examples without secret values in handover. This path’s models help reason about evidence; they do not execute Cosign, Trivy, a Docker build or an actual Kubernetes cluster.

IN PRACTICE

Six audit lines represent two requests, one denied. Correcting the count changes management’s impact report without removing evidence.

Common pitfalls

Assuming latest changes policy; treating filtering as fixing; confusing signatures with compliance; counting stages as changes; hiding audit gaps.

Related topics: Supply chain and secrets · Auditing and incident communication

Take this idea with you

Release decisions depend on clearly scoped evidence about the artifact, credentials and requests actually observed.

Create account

Reference: Container images · Kubernetes v1.35; current six-domain CKS outline

Kubernetes® and CKS are trademarks or registered trademarks of The Linux Foundation. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by The Linux Foundation. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.