Q: A sophisticated supply chain attack (similar to SolarWinds or Codecov) breaches your CI/CD runner environment and replaces a legitimate container image with a backdoored artifact before deployment. How do you design an enterprise software supply chain security platform compliant with SLSA Level 3 that cryptographically proves build provenance and guarantees that untrusted or tampered artifacts can never execute in Kubernetes?
Architectural blueprint for engineering a tamper-proof software supply chain security platform compliant with SLSA Level 3 using ephemeral CI runners, Sigstore Cosign cryptographic signing, and Kyverno admission controls.
Want to master this scenario in a live sandbox? The Linux Foundation's FinOps Certified Practitioner (FOCP) Program covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Enforce Hermetic Isolated Ephemeral CI Build Environments
Eliminate persistent build runner contamination vectors:
- Ephemeral Runners: Deployed single-use Virtual Machine runners via GitHub Actions Runner Controller (ARC) or AWS VMSS, terminated immediately after every single job.
- Hermetic Isolation: Builds execute inside isolated container runtimes with build parameters defined strictly as code; environment variables and network egress are locked down.
Generate Cryptographic In-Toto Provenance & Sigstore Attestations
Produce non-forgeable metadata documenting the exact build conditions:
- SLSA Generator: Integrated
slsa-github-generatorproducing an in-toto predicate declaring git repository, commit SHA, build configuration, and container SHA-256 digest. - Keyless Cosign Signing: Signed the container and provenance attestation using Sigstore Cosign via OIDC identity tokens, recording the cryptographic proof in the immutable Rekor public transparency log.
Automate Software Bill of Materials (SBOM) & Vulnerability Gates
Catalog all package dependencies and verify zero Critical CVEs:
- Syft SBOM Generation: Generated comprehensive Software Bill of Materials (SPDX / CycloneDX format) indexing all OS packages and npm/pip/go libraries.
- Trivy Vulnerability Scan: Scanned SBOM and container filesystem; signed the SBOM with Cosign only if zero unpatched Critical or High CVEs were detected.
Enforce Strict Cryptographic Verification at Kubernetes Admission (Kyverno)
Block any container lacking valid cryptographic signatures at the Kubernetes API server:
- Kyverno Policy: Deployed
ClusterPolicywithverifyImagesrule checking that the image is signed by the trusted GitHub Actions OIDC issuer and contains a valid SLSA Level 3 attestation. - Rejection Test: Attempted deploying an untampered image that was manually pushed by a developer; Kyverno rejected pod creation with HTTP 403 Forbidden.
- Tamper Detection: If even a single byte of a container layer is modified in the registry, the cryptographic digest check fails instantly.
- Execute builds on single-use ephemeral CI runners to prevent runner persistence attacks.
- Generate cryptographically signed SLSA Level 3 provenance using Sigstore Cosign and Rekor.
- Produce and sign Software Bill of Materials (SBOMs) with automated CVE gates.
- Enforce Kyverno admission controllers to reject any container lacking valid cryptographic attestations.