M4 · Identity and security
Supply chain
28 / 61

Shielded nodes verify the host; Binary Authorization verifies the release

These controls protect different transitions. Shielded GKE Nodes strengthen node identity and boot integrity; Binary Authorization enforces image deployment policy.

Shielded nodes

Built on Shielded VMs; enabled by default in Autopilot and default in Standard.

Attestation

Verifies the node is an expected Google-hosted machine and boot path.

Binary Authorization

Evaluates image policy before a workload is admitted.

Provenance

Trusted build and signing evidence supports the admission decision.

Host integrity cannot prove image provenance, and signed images still need runtime least privilege.