QuestionQ10

Implementing observability practices and troubleshooting issues

You are diagnosing an issue with an application running in a Google Kubernetes Engine (GKE) cluster that has Binary Authorization enabled. You need to run a temporary Pod for troubleshooting by using an unsigned utility container image from Artifact Registry. When you try to apply the Pod configuration from a YAML file, the Binary Authorization policy blocks the deployment. You must use the most secure and auditable solution to run the Pod. What should you do?

Explanation

Binary Authorization breakglass is an emergency, Pod-specific policy override enabled with the image-policy.k8s.io/break-glass: "true" label. It permits the otherwise denied image for that deployment while automatically recording a breakglass event in Cloud Audit Logs, preserving an auditable exception without weakening cluster-wide policy.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!