# Cis Gke Autopilot V100 4.5.1

> Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)

- Skill: `cyberstrikeus/cis-gke-autopilot-v100-4-5-1` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-gke-autopilot-v100-4-5-1`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-gke-autopilot-v100-4-5-1/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-gke-autopilot-v100-4-5-1

---


# 4.5.1 Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)

## Profile Applicability

- Level 2

## Description

Configure Image Provenance for the deployment.

## Rationale

Kubernetes supports plugging in provenance rules to accept or reject the images in deployments. Rules can be configured to ensure that only approved images are deployed in the cluster.

## Impact

Regular maintenance for the provenance configuration should be carried out, based on container image updates.

## Audit

Review the pod definitions in the cluster and verify that image provenance is configured as appropriate.

## Remediation

Follow the Kubernetes documentation and setup image provenance.

## Default Value

By default, image provenance is not set.

## References

1. https://kubernetes.io/docs/concepts/containers/images/
2. https://kubernetes.io/docs/reference/access-authn-authz/admission-controllers/

## CIS Controls

| Controls Version | Control                                            | IG 1 | IG 2 | IG 3 |
| ---------------- | -------------------------------------------------- | ---- | ---- | ---- |
| v8               | 4.6 Securely Manage Enterprise Assets and Software | \*   | \*   | \*   |
| v7               | 18 Application Software Security                   |      |      |      |

