
- Runtime protection (detecting and responding to threats in running workloads).
- Infrastructure and supply‑chain security (artifact provenance, signing, SBOMs).
- Security controls that preserve developer velocity (policy-as-code, automated gating).

Container image protection: scanning, signing, and supply‑chain metadata
Core practices for container image protection:- Use a registry (for example, Harbor) with integrated vulnerability scanning and RBAC.
- Scan images at build time (Trivy, Grype) and optionally continuously in the registry.
- Sign artifacts with tools such as Sigstore / Cosign and verify signatures before deployment.
- Record provenance and attestations with frameworks like in‑toto and generate SBOMs.

Typical CI/CD flow: build → scan → block on high/critical findings → sign → push to registry → verify at deployment. Example GitLab CI snippet demonstrating scanning and a separate signing stage:
Enforce signing and provenance at the registry/admission layer: platform teams should configure registry policies and admission controllers to reject unsigned or unaudited artifacts before they reach production clusters.
Runtime protection: Falco
Runtime protection monitors activity inside containers and hosts (system calls, execs, privilege escalation) and triggers alerts or automated responses. Falco is a CNCF project that provides system‑call level monitoring and rule‑based detection for Kubernetes and container runtimes.
Policy-as-code: OPA and Gatekeeper
Policy-as-code lets you declaratively express constraints and enforce them during admission. Open Policy Agent (OPA) uses the Rego language to express policies; Gatekeeper implements an admission controller that applies OPA policies and provides auditing.
- Block privileged containers and hostPath mounts.
- Enforce image provenance (require signature or specific registries).
- Validate resource requests/limits and labels for cost tracking.
Workload identity: SPIFFE and SPIRE
SPIFFE defines a standard identity format (SPIFFE ID) for workloads. SPIRE implements an attestation and identity issuance system that provides short‑lived X.509 certificates or JWTs to workloads. Combined with service meshes or TLS tooling, SPIFFE/SPIRE enable mTLS and zero‑trust networking.
Supply‑chain security: SLSA, SBOMs, and attestations
Supply‑chain security answers provenance questions: who built the artifact, what inputs were used, and can we trust the build process? Key concepts:- SLSA (Supply‑chain Levels for Software Artifacts) defines increasing levels of assurance.
- SBOMs (Software Bill of Materials) list components and versions.
- Attestations and in‑toto record and sign build pipeline steps.

- in‑toto: capture provenance and pipeline attestations.
- TUF (The Update Framework): secure distribution of updates.
- Notary v2 / Cosign: image signing and verification.

Automated compliance, auditing, and posture management
Combine policy engines, runtime monitoring, cloud security posture tools, and audit logging to automate compliance evidence collection and enforcement. These capabilities help demonstrate conformance to frameworks such as SOC 2, PCI‑DSS, FedRAMP, and NIST by codifying controls and collecting audit evidence.

Vulnerability management: Trivy, Grype, Snyk
Use scanners at multiple stages:- Build-time SCA/SAST (Trivy, Grype, Snyk).
- Pre-deployment checks (admission policies).
- Continuous scanning of running images and registries.

Security belongs across the pipeline: repository policies, build-time scans, signing, admission-time enforcement, runtime detection/response, and continuous post‑deployment monitoring. Include SAST/DAST and security testing in CI to shift left on finding issues.
Future trends
Expect growing use of AI in security (assist triage, predictive detection), increasing focus on edge security, and continued evolution of supply‑chain tools. Core practices that remain essential:- Regular container scanning and SBOMs.
- mTLS and workload identity for zero‑trust.
- Signed artifacts and attestations for provenance.

Essential building blocks for a Kubernetes-based platform
- Runtime protection (Falco) for real‑time detection and response.
- Workload identity (SPIFFE/SPIRE) for short‑lived identities and mTLS.
- Vulnerability management (Trivy/Grype/Snyk) for images, dependencies, and manifests.
- Policy enforcement (OPA/Gatekeeper) and automated compliance pipelines.
- Supply‑chain protections (SBOMs, in‑toto, TUF, Notary/Cosign) for provenance and signing.

Summary
This lesson provided a high‑level overview of the main categories of tools used in platform security:- Artifact protection (scanning, signing, SBOMs).
- Runtime protection (Falco and detection).
- Policy-as-code (OPA/Gatekeeper).
- Workload identity (SPIFFE/SPIRE).
- Supply‑chain attestations and SLSA.
- Automated compliance and vulnerability management.
Links and references
- Kubernetes Documentation
- OPA (Open Policy Agent)
- Falco Project
- SPIFFE / SPIRE
- Sigstore / Cosign
- Trivy
- Notary v2
- SLSA (Supply-chain Levels for Software Artifacts)