k8s-supply-chain-and-image-hardening

Installation
SKILL.md

Kubernetes Supply Chain and Image Hardening

When to use

Invoke when hardening a workload's container image, establishing the signing/SBOM/scan gate, or authoring the admission policy that enforces image trust at the cluster — or when auditing an inherited workload running unsigned, root, or unscanned images. This skill owns the hardening and enforcement; the security-context floor was set by the manifest archetype.

Do not use for: base manifest authoring (use k8s-workload-packaging-and-manifest); NetworkPolicy/RBAC and the PSS namespace floor (use k8s-network-and-identity-policy); autoscaler tuning (use k8s-scaling-and-resilience-topology); metrics/log/trace wiring (use k8s-observability-and-operations-readiness); the CI pipeline that executes the scan/sign steps (owned by the github-actions stack — this skill defines the gate and the admission policy, not the workflow); cluster provisioning and control-plane setup (out of Family G — owned by the cloud platform stack and Terraform).

Inputs

Required:

  • A container image or build from the language packaging sub-skill, and the workload manifest set from k8s-workload-packaging-and-manifest (the security-context floor this skill hardens and the image this skill signs/scans).
  • Approved architecture/security decisions on image-trust, scanning severity gate, and provenance posture, or explicit confirmation they are intentionally deferred.

Optional:

Installs
3
GitHub Stars
12
First Seen
Jun 10, 2026
k8s-supply-chain-and-image-hardening — amritmalla/claude-full-stack-2.0