Identity and security
Supply chain
39 / 69

Only trusted, scanned images should reach your nodes, and policy should refuse the rest.

1
Build
minimal base, non-root, SBOM
→
2
Push to ECR
immutable tags, scan on push
→
3
Sign
cosign or AWS Signer
→
4
Admit
policy engine verifies
→
5
Run
Pod Security enforced
ecr iconECR features

Immutable tags, lifecycle policies, scan on push, replication across regions, pull-through cache for public registries.

Admission policy engines

Kyverno or Gatekeeper can require signed images, trusted registries, resource requests and labels. Start in audit mode, then enforce.

Pin by digest

Tags can move. Deploy by digest, or enforce immutability, so what you scanned is what runs.

Kyverno: allow only our registry
kind: ClusterPolicy
spec:
  validationFailureAction: Audit        # switch to Enforce later
  rules:
  - name: trusted-registry
    match: {any: [{resources: {kinds: [Pod]}}]}
    validate:
      message: images must come from our ECR
      pattern: {spec: {containers: [{image: "111122223333.dkr.ecr.eu-west-1.amazonaws.com/*"}]}}