[{"data":1,"prerenderedAt":276},["ShallowReactive",2],{"blog-en-k3s-container-image-security-supply-chain-checklist":3,"blog-related-en-k3s-container-image-security-supply-chain-checklist":222,"blog-en-k3s-container-image-security-supply-chain-checklist-alt":210},{"id":4,"title":5,"author":6,"body":7,"date":204,"description":205,"extension":206,"image":207,"locale":208,"meta":209,"navigation":210,"path":211,"seo":212,"stem":213,"tags":214,"__hash__":221},"blog\u002Fblog\u002Fen\u002Fk3s-container-image-security-supply-chain-checklist.md","'Scanned' Is Not a Production Clearance Certificate: K3s Container Image Security From Signing to Admission Control","Kubo Team",{"type":8,"value":9,"toc":195},"minimark",[10,15,19,26,48,57,60,64,72,78,91,94,98,101,107,116,131,135,138,144,152,166,173,177,180],[11,12,14],"h2",{"id":13},"_1-have-you-stopped-thinking-once-you-added-a-scanner","1. Have You Stopped Thinking Once You Added a Scanner?",[16,17,18],"p",{},"When teams try to formalize container security guidelines, many stop at \"we introduced an image scanning tool.\" But installing a scanner and actually blocking a deployment based on its results are two completely different things.",[16,20,21],{},[22,23],"img",{"alt":24,"src":25},"section01","https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fk3s-container-image-security-supply-chain-checklist\u002Fsection01.webp",[16,27,28,29,33,34,41,42,47],{},"Running on the ",[30,31,32],"code",{},"latest"," tag, running containers as root, scans that run in CI but whose alerts nobody reads, and running images without signature verification at all — if even one of these applies to your setup, you risk introducing exactly the kind of known vulnerabilities described in ",[35,36,40],"a",{"href":37,"rel":38},"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fapplication-container-security-guide",[39],"nofollow","NIST's Application Container Security Guide"," into production without ever passing a real verification gate. Lightweight Kubernetes distributions like K3s (",[35,43,46],{"href":44,"rel":45},"https:\u002F\u002Fdocs.k3s.io\u002F",[39],"official K3s documentation",") are appealing because they're easy to set up, but that ease of setup must never become an excuse to skip security steps.",[16,49,50,51,56],{},"As a side note, plenty of teams say they simply don't have the capacity to build and operate all of this themselves. Using a managed K3s environment like ",[35,52,55],{"href":53,"rel":54},"https:\u002F\u002Fkubo.hexabase.io\u002F",[39],"Kubo"," as your foundation frees up that effort to focus on security design itself.",[16,58,59],{},"This article organizes the four gates a container image must pass through before it reaches production — minimal base images, vulnerability scanning, signing, and admission control — into a checklist you can use directly in practice.",[11,61,63],{"id":62},"_2-narrow-it-down-at-build-time-minimal-base-images-and-removing-root","2. Narrow It Down at Build Time — Minimal Base Images and Removing Root",[16,65,66,67,71],{},"The foundation of container security comes down to what you ",[68,69,70],"em",{},"don't"," include in the image. The attack surface grows in direct proportion to the number of files and binaries present inside the image.",[16,73,74],{},[22,75],{"alt":76,"src":77},"section02","https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fk3s-container-image-security-supply-chain-checklist\u002Fsection02.webp",[16,79,80,81,86,87,90],{},"Google's ",[35,82,85],{"href":83,"rel":84},"https:\u002F\u002Fgithub.com\u002FGoogleContainerTools\u002Fdistroless",[39],"distroless project"," provides minimal base images that exclude shells and package managers entirely, and Kubernetes itself has adopted this approach starting with v1.15. Multi-stage builds let you strip compilers and toolchains needed only for the build out of the final image completely. On top of that, explicitly setting ",[30,88,89],{},"USER"," in your Dockerfile to make non-root execution the default is a fundamental measure for reducing privilege escalation risk.",[16,92,93],{},"The same principles apply just as well to K3s clusters as to standard Kubernetes. If anything, the benefit of trimming risk at build time is even larger in environments like edge and on-premises deployments, where patch cycles tend to stretch out longer.",[11,95,97],{"id":96},"_3-catch-it-before-the-push-vulnerability-scanning-and-sbom-generation","3. Catch It Before the Push — Vulnerability Scanning and SBOM Generation",[16,99,100],{},"Even after narrowing down your base image, known CVEs in your application's own dependency libraries are unavoidable. What's needed here is making the pre-push scan function as an actual gate in your CI pipeline, not just a report.",[16,102,103],{},[22,104],{"alt":105,"src":106},"section03","https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fk3s-container-image-security-supply-chain-checklist\u002Fsection03.webp",[16,108,109,110,115],{},"The open-source ",[35,111,114],{"href":112,"rel":113},"https:\u002F\u002Ftrivy.dev\u002F",[39],"Trivy"," scanner detects CVEs and misconfigurations across container images, IaC configurations, and Kubernetes manifests, and its ease of CI integration has made it widely adopted. What matters isn't just \"running a scan\" — it's designing the pipeline so the build itself fails when Critical or High severity vulnerabilities are found. Without that, scan results end up as nothing more than a log nobody reads.",[16,117,118,119,124,125,130],{},"At the same time, generating an SBOM (Software Bill of Materials) for every image is essential. The two major SBOM standards are ",[35,120,123],{"href":121,"rel":122},"https:\u002F\u002Fcyclonedx.org\u002F",[39],"CycloneDX"," and ",[35,126,129],{"href":127,"rel":128},"https:\u002F\u002Fspdx.dev\u002F",[39],"SPDX",", both maintained as international specifications. Keeping an SBOM on hand means that when a new CVE is disclosed later, you can instantly identify which images contain the affected library, dramatically speeding up audit response and vulnerability triage.",[11,132,134],{"id":133},"_4-verify-before-deploy-signing-and-admission-control","4. Verify Before Deploy — Signing and Admission Control",[16,136,137],{},"Even after vulnerability scanning and SBOM generation are done, if the cluster can't confirm that an image is genuinely the one that passed CI, there's still room for a tampered image — or one that skipped scanning entirely — to slip through. This is where the combination of signing and admission control comes in.",[16,139,140],{},[22,141],{"alt":142,"src":143},"section04","https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fk3s-container-image-security-supply-chain-checklist\u002Fsection04.webp",[16,145,146,151],{},[35,147,150],{"href":148,"rel":149},"https:\u002F\u002Fgithub.com\u002Fsigstore\u002Fcosign",[39],"Cosign"," is a tool for attaching a digital signature to images built in a CI pipeline, and it also supports keyless signing that removes the need for key management. Signing alone doesn't accomplish much — it only becomes effective when paired with a mechanism that mechanically enforces a policy on the cluster side rejecting any unsigned image.",[16,153,154,155,124,160,165],{},"Admission controllers like ",[35,156,159],{"href":157,"rel":158},"https:\u002F\u002Fkyverno.io\u002Fdocs\u002Fpolicy-types\u002Fcluster-policy\u002Fverify-images\u002Foverview\u002F",[39],"Kyverno",[35,161,164],{"href":162,"rel":163},"https:\u002F\u002Fkubernetes.io\u002Fblog\u002F2019\u002F08\u002F06\u002Fopa-gatekeeper-policy-and-governance-for-kubernetes\u002F",[39],"OPA Gatekeeper"," take on this role. They evaluate policy at the Kubernetes API layer and reject any Pod creation request that doesn't meet the criteria. Because enforcement happens mechanically on the cluster side rather than relying on individual CI operators' diligence or oversight, you structurally prevent the accident where an image that slipped past scanning quietly ends up in production.",[16,167,168,169,172],{},"Maintaining signature verification and admission policies over time takes a meaningful amount of ongoing operational effort. In ",[35,170,55],{"href":53,"rel":171},[39],"'s K3s-based environment, automated certificate management via cert-manager and monitoring via Prometheus\u002FGrafana come built in standard, which reduces the surrounding operational load and lets you focus that effort on policy design itself.",[11,174,176],{"id":175},"_5-summary-bringing-the-four-gates-into-your-k3s-operations","5. Summary — Bringing the Four Gates Into Your K3s Operations",[16,178,179],{},"The four gates covered here — minimizing the base image, vulnerability scanning and SBOM generation, signing, and policy enforcement via admission control — are each insufficient on their own; they only function when chained together as a continuous pipeline. Runtime anomaly detection after a container starts running is out of scope for this article, since it belongs to a different defensive layer than the supply chain, and deserves its own dedicated treatment.",[16,181,182,183,188,189,194],{},"Building and maintaining this entire mechanism from scratch takes no small amount of effort — CI configuration, scanner operations, certificate and key management, and ongoing maintenance of admission controller policies. For organizations in regulated industries like finance or healthcare that need to keep their image supply chain management fully in-house for compliance reasons, ",[35,184,187],{"href":185,"rel":186},"https:\u002F\u002Fwww.hexabase.com\u002Fproduct\u002Fkubo\u002Fon-premise",[39],"Kubo On-Premise","'s air-gapped support is worth considering as an option. Take a moment to check whether your own container security practice has stalled at \"we run a scanner, so we're fine\" — run it against these four gates and see where it stands. If you'd like to discuss adoption, reach out via our ",[35,190,193],{"href":191,"rel":192},"https:\u002F\u002Fwww.hexabase.com\u002Fcontact-us\u002F",[39],"contact page",".",{"title":196,"searchDepth":197,"depth":197,"links":198},"",2,[199,200,201,202,203],{"id":13,"depth":197,"text":14},{"id":62,"depth":197,"text":63},{"id":96,"depth":197,"text":97},{"id":133,"depth":197,"text":134},{"id":175,"depth":197,"text":176},"2026-08-24","Container security guidelines often stop at 'we run a scanner.' This guide walks through the practical checklist you need to pass before production in K3s: minimal base images, vulnerability scanning, SBOM generation, signing, and admission control.","md","https:\u002F\u002Fcdn.kubo.hexabase.io\u002Fimages\u002Fblog\u002Fk3s-container-image-security-supply-chain-checklist\u002Feyecatch.webp","en",{},true,"\u002Fblog\u002Fen\u002Fk3s-container-image-security-supply-chain-checklist",{"title":5,"description":205},"blog\u002Fen\u002Fk3s-container-image-security-supply-chain-checklist",[215,216,217,218,219,220],"k3s","kubernetes","container-security","image-scanning","sbom","supply-chain-security","FxecuMFPIJsnji6MwZWKB39hRTRXVxYtqchF8L1LRv0",[223,232,242,250,259,266],{"path":224,"title":225,"description":226,"date":227,"tags":228},"\u002Fblog\u002Fen\u002Fk3s-harbor-private-registry-docker-hub-rate-limit","The Morning Docker Hub's Free Tier Freezes Up, Your K3s Cluster Quietly Grinds to a Halt: When to Run Your Own Harbor","Docker Hub's pull rate limit is an increasingly real risk to image pulls on production K3s clusters. Kubo explains the design decisions and hidden costs of self-hosting Harbor, a CNCF Graduated project.","2026-08-23",[215,216,229,230,231],"harbor","container-registry","cncf",{"path":233,"title":234,"description":235,"date":236,"tags":237},"\u002Fblog\u002Fen\u002Fkubernetes-cost-management-eks-aks-billing-visibility","Your EKS Bill Only Makes Sense at Month-End: Why Kubernetes Costs Are Structurally 'Discovered Too Late'","Why do Kubernetes costs on EKS\u002FAKS balloon unexpectedly? We break down how autoscaling and cross-AZ billing hide costs, and explore how K3s-based managed infrastructure turns them into a fixed cost.","2026-08-22",[215,216,238,239,240,241],"cost-optimization","managed-kubernetes","aks","finops",{"path":243,"title":244,"description":245,"date":246,"tags":247},"\u002Fblog\u002Fen\u002Fkubernetes-operations-specialization-managed-k3s-hiring","eBPF, cert-manager, Service Mesh: Why Kubernetes Operations Outgrew What One Engineer Can Handle","Why do Kubernetes operations roles stay unfilled for months? It isn't a lack of tool knowledge — it's that the discipline has splintered into too many specialties. Instead of hiring more heads, absorb the specialization into the platform with managed K3s.","2026-08-21",[215,216,239,248,249],"devops","platform-engineering",{"path":251,"title":252,"description":253,"date":254,"tags":255},"\u002Fblog\u002Fen\u002Fk3s-opentelemetry-observability-correlation","Stop Bouncing Between Three Dashboards: Correlating K3s Observability with OpenTelemetry","Are you burning incident-response time checking Prometheus, Loki, and Jaeger separately? Learn how to correlate metrics, logs, and traces with OpenTelemetry to cut investigation time on K3s clusters, with practical Collector deployment patterns.","2026-08-20",[215,216,256,257,258],"opentelemetry","observability","distributed-tracing",{"path":260,"title":261,"description":262,"date":263,"tags":264},"\u002Fblog\u002Fen\u002Fcncf-project-maturity-graduation-criteria-production","10,000 GitHub Stars Isn't a Diploma. Why the Real Criterion for Choosing a CNCF Project Isn't Commit Count but Maturity Stage","When adopting CNCF projects for your Kubernetes stack, are you judging them by GitHub stars and name recognition alone? Learn the Sandbox\u002FIncubating\u002FGraduated maturity framework and the Harbor case study to know what to check before production.","2026-08-19",[215,216,231,265,230],"oss-governance",{"path":267,"title":268,"description":269,"date":270,"tags":271},"\u002Fblog\u002Fen\u002Fai-agent-authentication-kubernetes-keycloak-spiffe","Don't Hand AI Agents the Keys. A Keyless Design for Authenticating MCP Servers on Kubernetes","Handing AI agents static API keys is an operating model that eventually breaks down. This article explains why static secrets hit a wall when running MCP servers on Kubernetes, and how Keycloak combined with SPIFFE\u002FSPIRE enables a 'keyless' authentication design.","2026-08-18",[215,216,272,273,274,275],"ai-agent","mcp","keycloak","zero-trust",1787649516154]