⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Platform Engineering & IDP Interview Questions Scenario 27 of 50 in Platform Engineering & IDP
Senior Platform Engineer Platform Engineering Platform Security & Secrets Supply Chain Security
🎯 Target Role / Context: Senior Platform Engineer Interview · Supply Chain Security

Q: Your security office mandates SLSA Level 3 compliance across all 400 engineering microservices. How do you integrate automated SBOM generation and keyless image signing into centralized platform CI workflows without breaking developer release velocity?

Baking cryptographic container image signing and Software Bill of Materials (SBOM) generation into centralized Golden Path CI workflows.

#Platform Engineering #Security #Cosign #SBOM #Syft #DevSecOps #Golden Paths
🎙️ Candidate Opening & Architectural Context
"Platform teams enforce supply chain integrity at the golden path level so application developers don't have to manage GPG keys or scan tooling. We embed Syft for SBOM generation and Sigstore Cosign for keyless OIDC signing directly into centralized GitHub Actions reusable workflows."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1

Automate SBOM Generation Using Syft in Golden Path Workflow

Immediately after Docker container build, execute Anchore Syft to generate a CycloneDX / SPDX JSON bill of materials and attach it to the OCI image registry.

- name: Generate SBOM
  uses: anchore/sbom-action@v0
  with:
    image: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }}
    format: spdx-json
    output-file: sbom.spdx.json
2

Execute Keyless Cosign Signing via GitHub Actions OIDC

Use Sigstore Cosign with GitHub's OIDC token (`id-token: write`). Cosign signs the image using short-lived Fulcio certificates, publishing signatures and SBOMs to the container registry without managing long-lived private keys.

- name: Sign Container Image
  run: |
    cosign sign --yes \
      ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }}
    cosign attach sbom --sbom sbom.spdx.json \
      ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }}
Advertisement
3

Enforce Admission Verification via Kyverno / Policy Controller

Deploy a Kyverno ClusterPolicy in Kubernetes blocking any container image that lacks a valid Cosign signature issued by the organization's GitHub repository identity.

Pro Tip: Developer Experience: Developers push code normally; signing and SBOM generation happen automatically in under 20 seconds during standard CI builds.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Secure the software supply chain transparently by integrating Syft SBOM generation and keyless Cosign OIDC signing into Golden Path reusable CI workflows."
⚡ 60-Second Elevator Pitch Talking Points
  • Generate automated SPDX/CycloneDX SBOMs during container build stages using Syft.
  • Sign container images keylessly using Sigstore Cosign and GitHub OIDC tokens.
  • Enforce signature verification in Kubernetes clusters via Kyverno admission webhooks.
Advertisement
Want more Platform Engineering & IDP scenarios?
Explore our complete collection of scenario-based Platform Engineering & IDP interview runbooks.
Browse All Platform Engineering & IDP Questions →