Skip to main content

k8s-supply-chain-and-image-hardening

Use when hardening the container image and enforcing supply-chain integrity for a Kubernetes workload after security and operations have decided the image-trust, scanning, and provenance posture. Produces minimal non-root read-only-root-FS images with dropped capabilities, image signing (cosign), SBOM generation (Syft), vulnerability scanning (Trivy/Grype) as a required gate, and admission-control policy (Kyverno/Gatekeeper) enforcing signed-image, non-root, and digest-pinned requirements at the cluster. This is the archetype-scoped successor to the security-context slice of the omnibus. Do not use for base manifest authoring, network/identity policy, autoscaler tuning, observability wiring, the CI pipeline that runs the gate, or cluster provisioning; use the other Family G archetype skills (pipeline wiring is the CI stack; cluster provisioning is out of family).

Aller à l'installation

Informations de source

Dépôt
aibot88/sec_skill_store
Dernière activité de la source
27 mai 2026 à 03:47
Langue détectée de SKILL.md
anglais
Étoiles
3
Forks
0

Options d'installation

Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.

Vérifiez les fichiers source

Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.