QuestionQ5

Building and implementing CI/CD pipelines, including continuous testing, for application, infrastructure, and machine learning workloads

You are configuring a CI/CD pipeline natively in Google Cloud. You want builds in a pre-production Google Kubernetes Engine (GKE) environment to be automatically load-tested before promotion to the production GKE environment. You must ensure that only builds that pass this test are deployed to production. You want to follow Google-recommended practices. How should you configure this pipeline with Binary Authorization?

Explanation

Binary Authorization can require a trusted attestation before an image is deployed to production. An automated load-test workload should create the attestation only after the test succeeds, using an asymmetric signing key held in Cloud KMS. Workload Identity Federation for GKE is the recommended way for a GKE workload to obtain the IAM authorization needed to use Google Cloud APIs, avoiding less-secure, long-lived service account JSON keys stored as Kubernetes Secrets.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!