Q: How do you handle container image security and AWS ECR repository management?
Comprehensive container image security and repository governance: automated CI vulnerability scanning with Trivy, image signing via Cosign, AWS ECR scan-on-push, tag immutability, and automated lifecycle policies to prevent registry bloat.
#Docker #AWS ECR #Security #Trivy #Cosign #Vulnerability Management #DevSecOps
🎙️ Candidate Opening & Architectural Context
"I enforce container security using a shift-left approach combined with registry governance: CI vulnerability scanning with Trivy/Grype, blocking critical CVEs before push, cryptographic signing with Cosign, and AWS ECR repository guardrails. In ECR, I enable Enhanced or Basic scan-on-push, enforce tag immutability to prevent overwriting production tags, configure lifecycle policies to purge untagged images, and restrict access using least-privilege IAM policies."
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
CI/CD Scanning with Trivy & Cryptographic Signing with Cosign
Block vulnerabilities before images ever reach the container registry:
# Scan image for critical CVEs in CI pipeline
trivy image --exit-code 1 --severity CRITICAL,HIGH \
--ignore-unfixed 123456789012.dkr.ecr.ap-south-1.amazonaws.com/api:v1.4.0
# Cryptographically sign the image using Cosign and AWS KMS
cosign sign --key awskms:///arn:aws:kms:ap-south-1:123456789012:key/cosign-key \
123456789012.dkr.ecr.ap-south-1.amazonaws.com/api:v1.4.0
- Automated Trivy Scan: Scan the built container image in CI, setting
--exit-code 1 --severity CRITICAL,HIGHto fail pipeline builds on unpatched vulnerabilities. - Cryptographic Image Signing: Use Sigstore Cosign with AWS KMS or OIDC keyless signing to attach a digital signature to the image manifest in ECR.
- Admission Enforcement: Deploy Kyverno or OPA Gatekeeper in Kubernetes to reject any pod whose image lacks a verified Cosign signature.
2️⃣
AWS ECR Tag Immutability, KMS Encryption & Lifecycle Policies
Enforce repository hygiene, data protection, and storage cost controls in AWS ECR:
# Create ECR repository with Tag Immutability and KMS encryption
aws ecr create-repository --repository-name payment-api \
--image-tag-mutability IMMUTABLE \
--encryption-configuration encryptionType=KMS,kmsKey=arn:aws:kms:ap-south-1:123456789012:key/ecr-key \
--image-scanning-configuration scanOnPush=true
# Apply lifecycle policy to expire untagged images after 3 days
aws ecr put-lifecycle-policy --repository-name payment-api \
--lifecycle-policy-text '{
"rules": [
{"rulePriority": 1, "description": "Expire untagged images", "selection": {"tagStatus": "untagged", "countType": "sinceImagePushed", "countUnit": "days", "countNumber": 3}, "action": {"type": "expire"}},
{"rulePriority": 2, "description": "Keep last 30 tagged", "selection": {"tagStatus": "any", "countType": "imageCountMoreThan", "countNumber": 30}, "action": {"type": "expire"}}
]
}'
- Tag Immutability: Enable immutable tags on production repositories so existing release tags cannot be overwritten by subsequent builds.
- KMS Customer Managed Encryption: Encrypt repositories using AWS KMS customer managed keys (CMKs) to satisfy compliance mandates.
- Lifecycle Rules: Configure automated JSON lifecycle policies to expire untagged images after 3 days and retain only the last 30 tagged production images to eliminate storage bloat.
- Scan on Push: Enable continuous vulnerability assessment in ECR to monitor for newly disclosed zero-day vulnerabilities in deployed images.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Shift security left by failing builds on critical CVEs with Trivy, sign images with Cosign, and protect AWS ECR with Tag Immutability, KMS CMKs, and automated lifecycle policies to prevent storage sprawl."
⚡ 60-Second Elevator Pitch Talking Points
- Block unpatched vulnerabilities in CI by scanning images with Trivy and signing manifests with Cosign.
- Enforce Tag Immutability and Scan on Push in AWS ECR to guarantee release tamper-proofing.
- Automate repository cost management using ECR lifecycle rules that expire untagged intermediate layers.
Advertisement