⚡ ~/naveed k8s
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Phase 3 — Security Module 18 of 24 Free & Open Access

Supply Chain Security & Admission Control

Complete production curriculum breakdown. Learn core architectural mechanics, study definitions in plain language, practice hands-on labs with the local minikube prod-sim cluster, and test active recall.

18 - Supply Chain Security & Admission Control

Why this matters

Hardening the cluster and the pods doesn't help if you're deploying a compromised or vulnerable image in the first place. This is "shift left" security applied to k8s.

Read this first — Definitions & Explanations

Supply chain risk

Attackers target images, dependencies, CI pipelines, and registries — not only running Pods.

Admission control for policy

Validating/mutating webhooks (OPA/Gatekeeper, Kyverno) can block bad images, force labels, deny :latest, require signatures, etc.

Image scanning

Scan for CVEs in CI and continuously in registries. Don’t ship known critical vulns blindly.

Image signing / verification

Ensure images come from trusted builders and weren’t tampered with (Sigstore/cosign-style workflows).

Avoid :latest in production

:latest moves. You lose reproducibility and auditability. Pin digests or immutable tags.

Official docs (read for detail)

Key Concepts

YouTube search terms

Hands-on lab (on prod-sim)

# Scan an image for CVEs with Trivy
brew install trivy   # or use the trivy container image
trivy image nginx:1.19   # old version, will show real CVEs
trivy image nginx:latest # compare

# Install Kyverno and write a real policy: block :latest tag cluster-wide
helm repo add kyverno https://kyverno.github.io/kyverno/
helm install kyverno kyverno/kyverno -n kyverno --create-namespace

cat <<EOF | kubectl apply -f -
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
  name: disallow-latest-tag
spec:
  validationFailureAction: Enforce
  rules:
  - name: require-image-tag
    match:
      any:
      - resources:
          kinds: ["Pod"]
    validate:
      message: "Using ':latest' tag is not allowed"
      pattern:
        spec:
          containers:
          - image: "!*:latest"
EOF

# Prove it blocks a bad deployment
kubectl run bad --image=nginx:latest   # should be denied by Kyverno
kubectl run good --image=nginx:1.27    # should succeed

# Add a second policy: require resource limits on every container
cat <<EOF | kubectl apply -f -
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
  name: require-resource-limits
spec:
  validationFailureAction: Enforce
  rules:
  - name: check-resources
    match:
      any:
      - resources:
          kinds: ["Pod"]
    validate:
      message: "CPU and memory limits are required"
      pattern:
        spec:
          containers:
          - resources:
              limits:
                memory: "?*"
                cpu: "?*"
EOF
kubectl run nolimit --image=nginx:1.27   # should be denied (no limits set)

Notes

(fill in your own words after watching + labbing)

📋 Self-Assessment Mastery Checklist (4 Competencies)
🧠 Practice Exam Questions (Module 18 MCQs)
⚡ Take Quiz & Save Progress in Tracker

Review these sample exam questions out loud, test your retrieval, and then unlock official scoring in the interactive tracker.

Question 1: Admission controllers can:
  • A. Validate/mutate requests before persistence
  • B. Schedule Pods onto nodes
  • C. Ship logs to Grafana
  • D. Replace kubelet
✓ Correct Answer: A (Validate/mutate requests before persistence)
Option A ('Validate/mutate requests before persistence') is the standard production architectural best practice.
Question 2: Image signing/verification aims to ensure:
  • A. Images come from trusted sources/integrity
  • B. Faster pulls always
  • C. Free LoadBalancers
  • D. Automatic HPA
✓ Correct Answer: A (Images come from trusted sources/integrity)
Option A ('Images come from trusted sources/integrity') is the standard production architectural best practice.
Question 3: Scanning images for CVEs should happen:
  • A. In CI and continuously, not only once
  • B. Only after production incidents
  • C. Only on worker nodes manually
  • D. Never if using latest tag
✓ Correct Answer: A (In CI and continuously, not only once)
Option A ('In CI and continuously, not only once') is the standard production architectural best practice.
Question 4: Avoid :latest in production because:
  • A. It is mutable and hard to track/reproduce
  • B. It disables RBAC
  • C. It breaks DNS
  • D. It cannot be pulled
✓ Correct Answer: A (It is mutable and hard to track/reproduce)
Option A ('It is mutable and hard to track/reproduce') is the standard production architectural best practice.
Question 5: OPA/Gatekeeper or Kyverno are used for:
  • A. Policy-as-code admission controls
  • B. Replacing etcd
  • C. CNI IPAM
  • D. metrics-server
✓ Correct Answer: A (Policy-as-code admission controls)
Option A ('Policy-as-code admission controls') is the standard production architectural best practice.
← Previous Module (17) Pod & Workload Security Next Module (19) → Runtime & Network Security