⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All FinOps & System Design Interview Questions Scenario 65 of 98 in FinOps & System Design
Staff Security Architect System Design DevSecOps & Supply Chain Security System Design

Q: A sophisticated supply chain attack (similar to SolarWinds or Codecov) breaches your CI/CD runner environment and replaces a legitimate container image with a backdoored artifact before deployment. How do you design an enterprise software supply chain security platform compliant with SLSA Level 3 that cryptographically proves build provenance and guarantees that untrusted or tampered artifacts can never execute in Kubernetes?

Architectural blueprint for engineering a tamper-proof software supply chain security platform compliant with SLSA Level 3 using ephemeral CI runners, Sigstore Cosign cryptographic signing, and Kyverno admission controls.

#System Design #Supply Chain Security #SLSA Level 3 #Cosign #Sigstore #Trivy #Kyverno
🎙️ Candidate Opening & Architectural Context
"Simply scanning container images for CVEs is insufficient—attackers can inject malicious binaries directly into the build pipeline. We architected a zero-trust software supply chain platform aligned with the SLSA (Supply-chain Levels for Software Artifacts) Level 3 framework using Sigstore Cosign, Rekor transparency logs, and Kyverno."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? The Linux Foundation's FinOps Certified Practitioner (FOCP) Program covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Enforce Hermetic Isolated Ephemeral CI Build Environments

Eliminate persistent build runner contamination vectors:

  • Ephemeral Runners: Deployed single-use Virtual Machine runners via GitHub Actions Runner Controller (ARC) or AWS VMSS, terminated immediately after every single job.
  • Hermetic Isolation: Builds execute inside isolated container runtimes with build parameters defined strictly as code; environment variables and network egress are locked down.
Pro Tip: Terminating build runners after every job eliminates persistent malware implants across pipeline executions.
2️⃣

Generate Cryptographic In-Toto Provenance & Sigstore Attestations

Produce non-forgeable metadata documenting the exact build conditions:

  • SLSA Generator: Integrated slsa-github-generator producing an in-toto predicate declaring git repository, commit SHA, build configuration, and container SHA-256 digest.
  • Keyless Cosign Signing: Signed the container and provenance attestation using Sigstore Cosign via OIDC identity tokens, recording the cryptographic proof in the immutable Rekor public transparency log.
Pro Tip: Keyless signing uses short-lived certificates bound to the CI/CD workflow identity, eliminating long-lived private signing keys that could be stolen.
3️⃣

Automate Software Bill of Materials (SBOM) & Vulnerability Gates

Catalog all package dependencies and verify zero Critical CVEs:

  • Syft SBOM Generation: Generated comprehensive Software Bill of Materials (SPDX / CycloneDX format) indexing all OS packages and npm/pip/go libraries.
  • Trivy Vulnerability Scan: Scanned SBOM and container filesystem; signed the SBOM with Cosign only if zero unpatched Critical or High CVEs were detected.
Pro Tip: Attaching a cryptographically signed SBOM directly to the container registry guarantees complete traceability during zero-day disclosure events.
4️⃣

Enforce Strict Cryptographic Verification at Kubernetes Admission (Kyverno)

Block any container lacking valid cryptographic signatures at the Kubernetes API server:

  • Kyverno Policy: Deployed ClusterPolicy with verifyImages rule checking that the image is signed by the trusted GitHub Actions OIDC issuer and contains a valid SLSA Level 3 attestation.
  • Rejection Test: Attempted deploying an untampered image that was manually pushed by a developer; Kyverno rejected pod creation with HTTP 403 Forbidden.
  • Tamper Detection: If even a single byte of a container layer is modified in the registry, the cryptographic digest check fails instantly.
Pro Tip: Kubernetes admission controllers act as the ultimate cryptographic gatekeeper, preventing unsigned or tampered artifacts from ever executing.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"SLSA Level 3 supply chain security requires ephemeral isolated build runners, keyless Sigstore Cosign provenance attestations, signed SBOMs, and Kyverno admission enforcement at the Kubernetes cluster level."
⚡ 60-Second Elevator Pitch Talking Points
  • Execute builds on single-use ephemeral CI runners to prevent runner persistence attacks.
  • Generate cryptographically signed SLSA Level 3 provenance using Sigstore Cosign and Rekor.
  • Produce and sign Software Bill of Materials (SBOMs) with automated CVE gates.
  • Enforce Kyverno admission controllers to reject any container lacking valid cryptographic attestations.
Advertisement
Want more FinOps & System Design scenarios?
Explore our complete collection of scenario-based FinOps & System Design interview runbooks.
Browse All FinOps & System Design Questions →