⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All CI/CD & GitOps Interview Questions Scenario 142 of 176 in CI/CD & GitOps
Senior DevOps / SRE CI/CD Container Security & DevSecOps Security Hardening

Q: Your security team discovers that developer container images running in production contain unpatched Critical CVEs and run as root with dangerous capabilities. How do you implement Aqua Trivy in CI/CD pipelines to scan container images and Dockerfiles, block builds with Critical fixable vulnerabilities, and export SARIF reports directly to GitHub Security?

Production guide for integrating Aqua Trivy into CI/CD pipelines to scan container images, Dockerfiles, and Helm charts for CVEs and security misconfigurations with automated build-blocking thresholds.

#CI/CD #Trivy #Containers #Docker #Security #Vulnerability Scanning #DevSecOps
🎙️ Candidate Opening & Architectural Context
"Deploying un-scanned container images into production leads to immediate CVE exploitation. We integrated Aqua Trivy into our container build pipelines to scan OS packages, language dependencies, and Dockerfile misconfigurations with automated severity-based build gates."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's Enterprise GitOps with ArgoCD & Kubernetes Rollouts covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Configure Trivy Container Image Scanning with Severity Filters

Scan newly built container images before pushing to registries:

  • Trivy Image Scan: Executed trivy image --severity HIGH,CRITICAL --ignore-unfixed --exit-code 1 payment-service:latest.
  • Ignore Unfixed CVEs: Setting --ignore-unfixed ensures the build fails only if a patched version of the vulnerable package actually exists in upstream repositories.
Pro Tip: Setting --exit-code 1 causes the CI step to fail immediately if matching vulnerabilities are found, halting the deployment pipeline.
2️⃣

Scan Dockerfile Misconfigurations & Secrets with Trivy Config

Catch insecure container configurations before image compilation:

  • Config Scanning: Executed trivy config ./Dockerfile.
  • Policy Checks: Trivy checks for compliance against CIS Docker Benchmarks: catching missing USER instructions (running as root), exposed sensitive ports, and missing health checks.
  • Secret Scanning: Scans the repository and image filesystem for leaked API keys, tokens, and private SSH certificates.
Pro Tip: Scanning Dockerfiles catches insecure defaults (like root execution) before wasting CPU compiling container image layers.
Advertisement
3️⃣

Export SARIF Reports & Upload to GitHub Code Scanning

Integrate findings natively into GitHub Advanced Security dashboards:

  • SARIF Export: Executed trivy image --format sarif --output trivy-results.sarif payment-service:latest.
  • Upload Action: Integrated github/codeql-action/upload-sarif@v3 with: { sarif_file: 'trivy-results.sarif' }.
  • GitHub Security Alerts: Vulnerabilities display directly in the GitHub repository's Security tab with remediation advice.
Pro Tip: SARIF integration provides a centralized security dashboard for compliance officers without digging through raw CI terminal logs.
4️⃣

Optimize Trivy Vulnerability Database Caching in CI Runners

Accelerate scanning speed by caching the vulnerability database:

  • DB Cache Sharing: Configured CI cache for ~/.cache/trivy, downloading differential DB updates in 4 seconds instead of 45 seconds.
  • Private Registry Push: Only images that pass 100% of Trivy gates are tagged and pushed to the enterprise container registry.
Pro Tip: Caching the Trivy DB prevents rate-limiting against GitHub releases and keeps security scans under 15 seconds.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Aqua Trivy provides comprehensive container security gating in CI/CD by scanning images and Dockerfiles for fixable High/Critical CVEs, blocking non-compliant builds, and exporting SARIF reports to GitHub Security."
⚡ 60-Second Elevator Pitch Talking Points
  • Scan container images with trivy image --severity HIGH,CRITICAL --ignore-unfixed --exit-code 1.
  • Scan Dockerfiles for CIS benchmark misconfigurations and embedded secrets with trivy config.
  • Export findings to SARIF format and upload directly to GitHub Code Scanning.
  • Cache the Trivy vulnerability database to keep scans blazing fast (<15 seconds).
Advertisement
Want more CI/CD & GitOps scenarios?
Explore our complete collection of scenario-based CI/CD & GitOps interview runbooks.
Browse All CI/CD & GitOps Questions →