Q: You need to enforce that every Docker image pushed to your internal container registry has been scanned for CVEs and has zero Critical severity vulnerabilities. How do you implement this as a hard gate in the CI pipeline and in the registry itself?
CI pipeline gate:
#CI/CD #๐ Supply Chain Security & Advanced CI/CD #L2 #DevOps #Automation #Pipelines
๐๏ธ Candidate Opening & Architectural Context
""During a high-stakes release, we hit a similar deployment challenge and resolved it with automated safeguards. The interviewer is testing: Container image scanning, registry admission controls, Trivy or Grype in CI.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
๐ ๏ธ Production Runbook & Step-by-Step Resolution
1๏ธโฃ
Initial Diagnostics & Root Cause Analysis
CI pipeline gate:
- ECR: Enable Enhanced Scanning (powered by Inspector). Set a lifecycle policy to deny pull of images tagged
:latestthat have Critical findings. - Harbor: Enable the Interrogation Service with Trivy. Set a project-level rule: "Prevent vulnerable images from running" at Critical threshold. Images failing the gate cannot be pulled by Kubernetes โ the
imagePullPolicyfails, preventing deployment.
2๏ธโฃ
Remediation & Permanent Safeguards
--exit-code 1 makes the job fail if any unfixed Critical CVEs are found. --ignore-unfixed skips CVEs where no upstream patch yet exists (reduces noise). Registry-level enforcement: Configure the registry (ECR, Harbor, or Artifactory) to enforce a scan policy:
- name: Scan image for CVEs
run: |
trivy image --exit-code 1 --severity CRITICAL \
--ignore-unfixed \
${{ env.IMAGE_TAG }}
๐ก The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: ECR: Enable Enhanced Scanning (powered by Inspector). Set a lifecycle policy to deny pull of images tagged :latest that have Criti."
โก 60-Second Elevator Pitch Talking Points
- ECR: Enable Enhanced Scanning (powered by Inspector). Set a lifecycle policy to deny pull of imag...
- Harbor: Enable the Interrogation Service with Trivy. Set a project-level rule: "Prevent vulnerabl...
Advertisement