← CKS: Kubernetes security in production
06 / 8 · 28 MIN

Artifacts, provenance, and vulnerabilities

Bind approval to exact content and matching evidence.

Concept and mechanism

A signature answers an integrity and identity question within the configured trust model. It does not automatically establish that the signer is approved for your application or that contents lack vulnerabilities. KubeLinter can analyze manifests and charts before release. A result without findings covers only the checks and inputs used; it establishes neither runtime behavior nor a valid signature. In keyless verification, constrain expected identity and issuer. Bind analysis and statements to the digest being promoted; an A report does not approve B because application names match. An SBOM inventory helps locate components when a vulnerability emerges. Confirm whether vulnerability scanning occurred or only inventory generation, which scanners were used, and when information was updated.

Guided application

Build a final image with components required for execution and keep build tools outside it where possible. Digest pinning provides reproducibility but requires a newly validated build to receive a base fix. During a hotfix, a manual container change disappears when another instance starts from the old image. Incorporate the fix into the declared delivery flow. At the release committee, present origin, digest, results, exceptions, and recovery as separate evidence. If a supplier delivers an unapproved signer identity and a report for another digest, communicate the gap and options for delay or a prior version. Do not edit the report to fabricate correspondence.

IN PRACTICE

A valid signature from an unapproved repository fails origin policy; a clean scan of another digest does not resolve it.

Common pitfalls

Signature treated as flaw-free; SBOM treated as scan; tag treated as fixed content; manual hotfix treated as reproducible release.

Related topics: Auditing and evidence preservation · Runtime detection and coordinated response

Take this idea with you

Approval should follow the exact artifact and every required trust condition.

Create account

Reference: Cosign verification · Kubernetes v1.35; current six-domain CKS outline