QuestionQ265

Deploying applications

You work for a financial-services company that follows a container-first approach. Your team develops microservices applications. You have a Cloud Build pipeline that builds a container image, runs regression tests, and publishes the image to Artifact Registry. You need to ensure that only containers that passed the regression tests are deployed to GKE clusters. Binary Authorization is already enabled on the GKE clusters. What should you do next?

  • A Deploy Voucher Server and Voucher Client components. After a container image has passed the regression tests, run Voucher Client as a step in the Cloud Build pipeline.
  • B Create an attestor and a policy. Run a vulnerability scan to create an attestation for the container image as a step in the Cloud Build pipeline.
  • C Create an attestor and a policy. Create an attestation for the container images that have passed the regression tests as a step in the Cloud Build pipeline.
  • D Set the Pod Security Standard level to Restricted for the relevant namespaces. Digitally sign the container images that have passed the regression tests as a step in the Cloud Build pipeline.
Explanation

Binary Authorization policies can require attestations from specified attestors before an image is deployed. An attestation created only after a container image passes regression testing provides the required verifiable evidence, and a policy that requires that attestor blocks images without it from deployment.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!