K8S Supply Chain And Image Hardening

Use when hardening the container image and enforcing supply-chain integrity for a Kubernetes workload after security and operations have decided the image-trust, scanning, and provenance posture. Produces minimal non-root read-only-root-FS images with dropped capabilities, image signing (cosign), SBOM generation (Syft), vulnerability scanning (Trivy/Grype) as a required gate, and admission-control policy (Kyverno/Gatekeeper) enforcing signed-image, non-root, and digest-pinned requirements at the cluster. This is the archetype-scoped successor to the security-context slice of the omnibus. Do not use for base manifest authoring, network/identity policy, autoscaler tuning, observability wiring, the CI pipeline that runs the gate, or cluster provisioning; use the other Family G archetype skills (pipeline wiring is the CI stack; cluster provisioning is out of family).

aibot88 Updated 3 repo stars

File contents

aibot88/sec_skill_store/tree/main/skills/claudskills/k8s-supply-chain-and-image-hardening commit 3add77d506

Frequently asked questions

npx skillmds@latest add aibot88/k8s-supply-chain-and-image-hardening