โšก ~/naveed Interview Prep
โšก Portfolio Home โœ๏ธ Engineering Blog Deep Dives ๐ŸŽฏ Interview Hub 998+ Scenarios โ˜ธ๏ธ Kubernetes Mastery Hub 24 Modules ๐ŸŽฎ DevOps Arcade & Quizzes Subnet Blitz โšก ๐Ÿ—บ๏ธ DevOps Roadmaps PDFs & Guides ๐Ÿค– Morpheus Analysis AI Quant โ†— ๐Ÿ› ๏ธ Developer Tools Utilities ๐Ÿงช Labs & Experiments ๐Ÿ“„ Interactive CV & Certs ๐Ÿ”— All Links & Socials โšก Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE [L2] CI/CD ๐Ÿ” Supply Chain Security & Advanced CI/CD Production Scenario [L2]

Q: You need to enforce that every Docker image pushed to your internal container registry has been scanned for CVEs and has zero Critical severity vulnerabilities. How do you implement this as a hard gate in the CI pipeline and in the registry itself?

CI pipeline gate:

#CI/CD #๐Ÿ” Supply Chain Security & Advanced CI/CD #L2 #DevOps #Automation #Pipelines
๐ŸŽ™๏ธ Candidate Opening & Architectural Context
""During a high-stakes release, we hit a similar deployment challenge and resolved it with automated safeguards. The interviewer is testing: Container image scanning, registry admission controls, Trivy or Grype in CI.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

๐Ÿ› ๏ธ Production Runbook & Step-by-Step Resolution

1๏ธโƒฃ

Initial Diagnostics & Root Cause Analysis

CI pipeline gate:

  • ECR: Enable Enhanced Scanning (powered by Inspector). Set a lifecycle policy to deny pull of images tagged :latest that have Critical findings.
  • Harbor: Enable the Interrogation Service with Trivy. Set a project-level rule: "Prevent vulnerable images from running" at Critical threshold. Images failing the gate cannot be pulled by Kubernetes โ€” the imagePullPolicy fails, preventing deployment.
2๏ธโƒฃ

Remediation & Permanent Safeguards

--exit-code 1 makes the job fail if any unfixed Critical CVEs are found. --ignore-unfixed skips CVEs where no upstream patch yet exists (reduces noise). Registry-level enforcement: Configure the registry (ECR, Harbor, or Artifactory) to enforce a scan policy:

- name: Scan image for CVEs
  run: |
    trivy image --exit-code 1 --severity CRITICAL \
      --ignore-unfixed \
      ${{ env.IMAGE_TAG }}
๐Ÿ’ก The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: ECR: Enable Enhanced Scanning (powered by Inspector). Set a lifecycle policy to deny pull of images tagged :latest that have Criti."
โšก 60-Second Elevator Pitch Talking Points
  • ECR: Enable Enhanced Scanning (powered by Inspector). Set a lifecycle policy to deny pull of imag...
  • Harbor: Enable the Interrogation Service with Trivy. Set a project-level rule: "Prevent vulnerabl...
Advertisement
Want more CI/CD scenarios?
Explore our complete collection of scenario-based CI/CD interview runbooks.
Browse All CI/CD Questions →

๐Ÿ“š Related Production Scenarios in CI/CD