Runbook 01 — Container Image Security Assessment
Runbook Information
Section titled “Runbook Information”| Item | Details |
|---|---|
| Runbook ID | K8S-IMAGE-RUNBOOK-01 |
| Category | Container Image Security Assessment |
| Runbook Type | Enterprise Security Assessment |
| Primary Team | Kubernetes Security Engineering |
| Supporting Teams | DevSecOps, Platform Engineering, Cloud Security, Application Security, SOC |
| Estimated Duration | 4–8 Hours |
| Review Frequency | Monthly / Before Production Release |
| Environment | Kubernetes Production & Non-Production Clusters |
| Compliance Alignment | CIS Kubernetes Benchmark, NIST SP 800-190, SLSA, NIST SSDF, OWASP Kubernetes Top 10 |
Executive Summary
Section titled “Executive Summary”Container images are the foundation of every Kubernetes workload.
Compromised or poorly managed images introduce significant risks, including:
- Remote code execution
- Supply chain attacks
- Malware
- Embedded credentials
- Outdated packages
- Untrusted software
- Dependency confusion
- Privilege escalation
- Regulatory non-compliance
This runbook provides a structured enterprise methodology for assessing container image security throughout the software supply chain—from source code and image creation through deployment into Kubernetes.
Enterprise Scenario
Section titled “Enterprise Scenario”CloudNova Technologies deploys hundreds of containerised microservices across multiple Kubernetes clusters.
Following a third-party security assessment, several critical weaknesses were identified:
- Images built from unsupported base operating systems
- Root containers
- Images pulled directly from Docker Hub
- Mutable image tags
- Missing SBOMs
- Missing image signatures
- Missing vulnerability scans
- Excessive image sizes
- Embedded cloud credentials
- No admission enforcement
- Inconsistent registry governance
The CISO has requested a comprehensive assessment of the organisation’s container image security programme before approving further production releases.
Assessment Objectives
Section titled “Assessment Objectives”Validate that:
- Images originate from trusted sources
- Secure image build standards are followed
- Base images are approved
- Images are scanned before deployment
- Secrets are not embedded
- SBOMs are generated
- Images are signed
- Registry governance is enforced
- Admission policies validate trust
- Kubernetes workloads deploy only approved images
- Image lifecycle management exists
- Evidence supports audit and compliance
Enterprise Image Security Architecture
Section titled “Enterprise Image Security Architecture”Developer
│
▼
Source Repository
│
▼
CI/CD Pipeline
│
▼
Secure Image Build
│
▼
Image Scan
│
▼
SBOM Generation
│
▼
Image Signing
│
▼
Private Registry
│
▼
Admission Controller
│
▼
Kubernetes Cluster
│
▼
Runtime MonitoringAssessment Scope
Section titled “Assessment Scope”Review:
- Dockerfiles
- Base Images
- Build Pipelines
- CI/CD Systems
- Container Registries
- Image Scanning
- SBOM Generation
- Image Signing
- Image Attestations
- Admission Policies
- Kubernetes Deployments
- Running Pods
- Runtime Images
- Registry Permissions
- Registry Audit Logs
Required Tools
Section titled “Required Tools”| Tool | Purpose |
|---|---|
| kubectl | Cluster Review |
| Docker | Image Inspection |
| Trivy | Vulnerability Assessment |
| Cosign | Signature Verification |
| Syft | SBOM Review |
| jq | JSON Analysis |
| Helm | Controller Validation |
| Git | Source Review |
Assessment Workflow
Section titled “Assessment Workflow”Image Inventory
│
▼
Build Review
│
▼
Image Scan
│
▼
Registry Review
│
▼
Signature Review
│
▼
Admission Review
│
▼
Runtime Validation
│
▼
Risk Assessment
│
▼
Security ReportPhase 1 — Image Inventory
Section titled “Phase 1 — Image Inventory”Collect all running images.
kubectl get pods -A \-o=jsonpath="{..image}"List unique images.
Identify:
- Registry
- Repository
- Tag
- Digest
- Namespace
- Owner
Review:
- Public Images
- Private Images
- Deprecated Images
- Duplicate Images
Phase 2 — Base Image Assessment
Section titled “Phase 2 — Base Image Assessment”Review:
- Operating System
- Base Image Version
- Support Status
- Vendor
Validate:
- Official Image
- Supported Distribution
- Security Updates
- Minimal Image
Reject:
- End-of-Life Images
- Unknown Images
- Community Images without approval
Phase 3 — Dockerfile Review
Section titled “Phase 3 — Dockerfile Review”Assess:
- Multi-stage Builds
- Root User
- Package Manager
- Secrets
- COPY Commands
- ADD Usage
- Layer Optimisation
- .dockerignore
Validate:
- Non-root User
- Minimal Runtime
- Secure Defaults
Phase 4 — Image Vulnerability Assessment
Section titled “Phase 4 — Image Vulnerability Assessment”Review.
trivy image IMAGEValidate.
- Critical
- High
- Medium
- Low
Review.
- Fixed Versions
- Unfixed
- Exploitability
Confirm.
Risk Acceptance documented.
Phase 5 — Secret Assessment
Section titled “Phase 5 — Secret Assessment”Review.
trivy image \--scanners secretSearch.
- API Keys
- Tokens
- Passwords
- Certificates
- Private Keys
Reject.
Embedded Secrets.
Phase 6 — SBOM Assessment
Section titled “Phase 6 — SBOM Assessment”Review.
- CycloneDX
- SPDX
Validate.
- Package Inventory
- Dependencies
- Versions
- Licences
Confirm.
SBOM linked to image digest.
Phase 7 — Registry Assessment
Section titled “Phase 7 — Registry Assessment”Review.
- Registry Type
- Private Access
- Encryption
- IAM
- Tag Immutability
- Lifecycle Policies
Reject.
- Public Production Images
- Mutable Production Tags
Phase 8 — Image Signing Assessment
Section titled “Phase 8 — Image Signing Assessment”Validate.
cosign verifyConfirm.
- Signature
- Trusted Key
- Trusted Identity
- Trusted Issuer
Reject.
Unsigned Images.
Phase 9 — Attestation Assessment
Section titled “Phase 9 — Attestation Assessment”Validate.
- SBOM
- Vulnerability Scan
- Build Provenance
- Security Approval
Review.
Predicate Types.
Phase 10 — Admission Policy Assessment
Section titled “Phase 10 — Admission Policy Assessment”Review.
- Trusted Registry
- Digest Enforcement
- Signature Enforcement
- SBOM Validation
- Trusted Identities
Confirm.
Audit Mode
Enforce Mode
Phase 11 — Kubernetes Deployment Review
Section titled “Phase 11 — Kubernetes Deployment Review”Review.
kubectl get deployments -AValidate.
- Image Digest
- No latest Tags
- Private Registry
- Approved Images
Phase 12 — Runtime Validation
Section titled “Phase 12 — Runtime Validation”Review.
Running Images.
kubectl get pods -A \-o wideValidate.
Running Digest.
Running User.
Running Registry.
Phase 13 — Registry IAM Assessment
Section titled “Phase 13 — Registry IAM Assessment”Review.
- Push Roles
- Pull Roles
- Admin Roles
Validate.
Least Privilege.
Phase 14 — Image Lifecycle Review
Section titled “Phase 14 — Image Lifecycle Review”Validate.
- Retention
- Archive
- Delete Protection
- Rollback Images
Phase 15 — Audit Logging Review
Section titled “Phase 15 — Audit Logging Review”Review.
Registry Logs.
CI/CD Logs.
Admission Logs.
Deployment Logs.
Phase 16 — Software Supply Chain Assessment
Section titled “Phase 16 — Software Supply Chain Assessment”Review.
- Source
- Build
- Scan
- SBOM
- Signature
- Registry
- Admission
- Runtime
Compare against.
SLSA
NIST SSDF
Enterprise Assessment Checklist
Section titled “Enterprise Assessment Checklist”| Control | Status |
|---|---|
| Trusted Base Images | ☐ |
| Supported OS | ☐ |
| Minimal Images | ☐ |
| Multi-stage Builds | ☐ |
| Non-root Images | ☐ |
| Secrets Removed | ☐ |
| Image Scan | ☐ |
| Critical Risks Reviewed | ☐ |
| SBOM Generated | ☐ |
| Signature Verified | ☐ |
| Trusted Registry | ☐ |
| Immutable Tags | ☐ |
| Digest Deployment | ☐ |
| Admission Policies | ☐ |
| Runtime Validation | ☐ |
| Registry IAM | ☐ |
| Lifecycle Policy | ☐ |
| Audit Logging | ☐ |
| Evidence Collected | ☐ |
Risk Classification
Section titled “Risk Classification”Critical
Section titled “Critical”- Unsigned Production Images
- Public Registry Images
- Embedded Secrets
- Unsupported Base Images
- No Admission Controls
- Root Containers
- Missing SBOM
- Mutable Tags
- Missing Image Scan
- Registry Misconfiguration
Medium
Section titled “Medium”- Large Images
- Missing Labels
- Weak Documentation
- Metadata
- Naming Standards
- Minor Optimisations
Remediation Priorities
Section titled “Remediation Priorities”Immediate
Section titled “Immediate”- Remove unsigned images
- Remove embedded secrets
- Replace unsupported base images
- Enable vulnerability scanning
- Enforce digest-based deployments
Short-Term
Section titled “Short-Term”- Generate SBOMs
- Implement image signing
- Configure registry lifecycle policies
- Restrict registry IAM
- Enable admission enforcement
Long-Term
Section titled “Long-Term”- Implement SLSA Level improvements
- Automate build provenance
- Continuous image scanning
- Automated policy validation
- Enterprise supply-chain monitoring
Enterprise Assessment Matrix
Section titled “Enterprise Assessment Matrix”| Area | Rating |
|---|---|
| Build Security | |
| Base Images | |
| Registry Security | |
| Image Scanning | |
| SBOM | |
| Image Signing | |
| Attestations | |
| Admission Control | |
| Runtime Validation | |
| Compliance |
Ratings:
- Effective
- Partially Effective
- Ineffective
Evidence Collection
Section titled “Evidence Collection”Collect:
- Dockerfiles
- Image Inventory
- Image Scan Reports
- Secret Scan Reports
- SBOM Files
- Signature Verification
- Registry Policies
- Admission Policies
- Deployment YAML
- Runtime Images
- Audit Logs
- Assessment Results
Enterprise Assessment Report
Section titled “Enterprise Assessment Report”Assessment Name:
Container Image Security Assessment
Assessment Date:
Assessor:
Environment:
Cluster:
Namespaces Reviewed:
Images Reviewed:
Critical Findings:
High Findings:
Medium Findings:
Low Findings:
Unsigned Images:
Images without SBOM:
Images without Scan:
Public Registry Images:
Mutable Tags:
Registry Security:
Image Signing:
Admission Policies:
Overall Risk:
Recommendations:
Production Approval:
Approved
Conditionally Approved
RejectedSuccess Criteria
Section titled “Success Criteria”The assessment is successful when:
- Every production image is inventoried.
- Only approved base images are used.
- Images are vulnerability scanned.
- Secrets are absent.
- SBOMs exist.
- Images are signed.
- Registry controls are enforced.
- Admission policies validate deployments.
- Runtime images match approved digests.
- Evidence is retained.
- Security report is completed.
Operational Best Practices
Section titled “Operational Best Practices”- Monitor new image pushes
- Review critical vulnerability alerts
- Review failed admission events
Weekly
Section titled “Weekly”- Review registry access
- Validate image signatures
- Scan newly released images
Monthly
Section titled “Monthly”- Complete full image security assessment
- Review SBOM inventory
- Review registry lifecycle policies
- Audit trusted signing identities
Quarterly
Section titled “Quarterly”- Review software supply chain maturity
- Rotate signing keys
- Test incident response procedures
- Review admission policy effectiveness
Runbook Summary
Section titled “Runbook Summary”This runbook provides a complete enterprise methodology for assessing Kubernetes container image security across the entire software supply chain.
It validates every stage of the image lifecycle—from secure image creation and vulnerability scanning to SBOM generation, image signing, private registry governance, admission policy enforcement, and runtime deployment verification.
By following this assessment process, organisations can ensure that only trusted, verified, and policy-compliant container images are deployed into Kubernetes, reducing the risk of supply chain attacks, image tampering, embedded secrets, and unauthorised software reaching production.
What’s Next?
Section titled “What’s Next?”Next Runbook: Runbook 02 — Enterprise Container Registry Security Assessment
In the next runbook, you will perform a comprehensive security assessment of enterprise container registries, including repository governance, IAM and RBAC controls, encryption, tag immutability, lifecycle management, vulnerability scanning, registry audit logging, replication, backup, incident response readiness, and compliance with enterprise container registry security standards.