4.5.1 Enforce image provenance using Binary Authorization for GKE

Information

Use Binary Authorization for GKE to enforce image provenance and deploy time trust policies before container images are admitted to the GKE Autopilot cluster. Policies should allow only approved images, trusted registries, or images with required attestations from approved build, security, or release processes.

Binary Authorization provides centralized policy enforcement for GKE deployments by evaluating container images at deploy time. When attestation based rules are used, the policy verifies that an image digest has been signed by a trusted attestor before the workload is allowed to run. This helps prevent unapproved, unsigned, unverified, or noncompliant images from being deployed, even if a user or pipeline has permission to create Kubernetes workloads.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Enable Binary Authorization enforcement for the GKE Autopilot cluster and configure the policy to block unapproved images at deploy time. Use approved image rules, trusted registries, or attestation based requirements aligned to the build, security scan, and release approval process. Validate the policy in dry run or a lower environment before enforcing broadly in production.

Impact:

Enforcing Binary Authorization can block deployments that do not match the configured policy, including images missing required attestations or images from unapproved sources.

See Also

https://workbench.cisecurity.org/benchmarks/24958

Item Details

Category: CONFIGURATION MANAGEMENT, MAINTENANCE

References: 800-53|CM-7, 800-53|MA-4, CSCv7|18

Plugin: GCP

Control ID: 496ea59cee923731497856fe03304cf8deb8277f4d269ae542a5c0f3e760deea