k8s-supply-chain-and-image-hardening
Kubernetes Supply Chain and Image Hardening
When to use
Invoke when hardening a workload's container image, establishing the signing/SBOM/scan gate, or authoring the admission policy that enforces image trust at the cluster — or when auditing an inherited workload running unsigned, root, or unscanned images. This skill owns the hardening and enforcement; the security-context floor was set by the manifest archetype.
Do not use for: base manifest authoring (use k8s-workload-packaging-and-manifest); NetworkPolicy/RBAC and the PSS namespace floor (use k8s-network-and-identity-policy); autoscaler tuning (use k8s-scaling-and-resilience-topology); metrics/log/trace wiring (use k8s-observability-and-operations-readiness); the CI pipeline that executes the scan/sign steps (owned by the github-actions stack — this skill defines the gate and the admission policy, not the workflow); cluster provisioning and control-plane setup (out of Family G — owned by the cloud platform stack and Terraform).
Inputs
Required:
- A container image or build from the language packaging sub-skill, and the workload manifest set from
k8s-workload-packaging-and-manifest(the security-context floor this skill hardens and the image this skill signs/scans). - Approved
architecture/securitydecisions on image-trust, scanning severity gate, and provenance posture, or explicit confirmation they are intentionally deferred.
Optional: