QuestionQ288
Deploying applicationsYou are creating a container-build pipeline for an application hosted on GKE. You have these requirements:
- Only images produced through your build pipeline must be deployed to your GKE cluster.
- All code and build artifacts must remain in your environment and be protected against data exfiltration.
How should you build the pipeline?
- A
- Create a build pipeline by using Cloud Build with the default worker pool.2. Deploy container images to a private container registry in your VPC.3. Create a VPC firewall policy in your project that denies all egress and ingress traffic to public networks.
- B
- Create a build pipeline by using Cloud Build with a private worker pool.2. Use VPC Service Controls to place all components and services in your CI/CD pipeline inside a security perimeter.3. Configure your GKE cluster to only allow container images signed by Binary Authorization.
- C
- Create a build pipeline by using Cloud Build with a private worker pool.2. Configure the CI/CD pipeline to build container images and store them in Artifact Registry.3. Configure Artifact Registry to encrypt container images by using customer-managed encryption keys (CMEK).
- D
- Create a build pipeline by using Cloud Build with the default worker pool.2. Configure the CI/CD pipeline to build container images and store them in Artifact Registry.3. Configure your GKE cluster to only allow container images signed by Binary Authorization.
Community Discussion