Supply-Chain-Aware CI/CD for Regulated Enterprises: Integrating Artifact Signing, Secret Injection and Promotion Gates in Kubernetes-Native Pipelines

Authors

  • Kartheek Reddy Jinna Specialist, LTIMindtree Ltd, Edison, New Jersey, USA Author
  • Senthil Kumar Subramani IP Verification Lead, Celestial AI, Folsom, California, USA Author

DOI:

https://doi.org/10.15680/IJCTECE.2022.0506028

Keywords:

software supply chain security, CI/CD, SLSA, artifact signing, secrets management, Kubernetes, Tekton

Abstract

The SolarWinds compromise of 2020 and the Codecov incident of 2021 showed that build pipelines are part of the attack surface: one altered source during compilation beneath a valid signature, the other harvested long-lived credentials from continuous integration jobs. Regulated enterprises now face supplier and regulatory expectations for provenance, signing and software bills of materials, yet most still operate pipelines designed only for speed and change-ticket compliance. We present a reference design for Kubernetes-native Tekton pipelines aligned with the Supply-chain Levels for Software Artifacts (SLSA) framework. The design combines platform-generated in-toto provenance, Sigstore cosign image signing, HashiCorp Vault dynamic secret injection in place of static credentials, and policy-gated promotion of digest-pinned artifacts through Dev, UAT and Prod repositories, enforced again at Kubernetes admission. We define four trust boundaries, five attestation points and a threat-to-control mapping that extends the SLSA threats with secret theft and pipeline-definition tampering. In a controlled evaluation with twelve services and 480 runs per design, we compare a conventional Jenkins pipeline, a hardened Jenkins pipeline and the proposed design on stage-wise latency, a Secret Exposure Index, threat coverage and audit evidence completeness. The Kubernetes-native design covers 19 of 20 threat-control points, reduces the Secret Exposure Index from 100 to 1.9, and raises digest-bound evidence completeness from 41% to 99% at a median latency overhead of 7.9%, against 13.2% for the hardened Jenkins design. We report the operational cost of each control and a practical adoption order.

15 9

References

[1] FireEye, "Highly evasive attacker leverages SolarWinds supply chain to compromise multiple global victims with SUNBURST backdoor," FireEye Threat Research Blog, Dec. 2020.

[2] CrowdStrike Intelligence Team, "SUNSPOT: An implant in the build process," CrowdStrike Blog, Jan. 2021.

[3] Codecov, "Bash Uploader security update," Codecov security notice, Apr. 2021.

[4] Executive Office of the President, "Executive Order 14028: Improving the Nation's Cybersecurity," Federal Register, vol. 86, no. 93, pp. 26633-26647, May 2021.

[5] CNCF Security Technical Advisory Group, "Software supply chain best practices," v1.0, Cloud Native Computing Foundation, May 2021.

[6] Cybersecurity and Infrastructure Security Agency and National Institute of Standards and Technology, "Defending against software supply chain attacks," Apr. 2021.

[7] Tekton Project, "Tekton Pipelines documentation: Tasks, Pipelines, Workspaces and PipelineRuns," tekton.dev, 2021.

[8] Sigstore Project, "cosign: Container signing, verification and storage in an OCI registry," GitHub repository sigstore/cosign, 2021.

[9] HashiCorp, "Vault documentation: Kubernetes auth method, Agent sidecar injector, and dynamic secrets engines," vaultproject.io, 2021.

[10] JFrog, "Artifactory REST API: Build promotion and Docker image promotion," JFrog product documentation, 2021.

[11] K. Lewandowski and M. Lodato, "Introducing SLSA, an end-to-end framework for supply chain integrity," Google Security Blog, Jun. 2021.

[12] SLSA Project, "Supply-chain Levels for Software Artifacts (SLSA), version 0.1: Requirements and threats," slsa.dev, 2021.

[13] M. Ohm, H. Plate, A. Sykosch, and M. Meier, "Backstabber's knife collection: A review of open source software supply chain attacks," in Proc. Int. Conf. Detection of Intrusions and Malware, and Vulnerability Assessment (DIMVA), LNCS vol. 12223, Springer, 2020.

[14] M. Zimmermann, C.-A. Staicu, C. Tenny, and M. Pradel, "Small world with high risks: A study of security threats in the npm ecosystem," in Proc. 28th USENIX Security Symposium, 2019, pp. 995-1010.

[15] J. Samuel, N. Mathewson, J. Cappos, and R. Dingledine, "Survivable key compromise in software update systems," in Proc. 17th ACM Conf. Computer and Communications Security (CCS), 2010, pp. 61-72.

[16] S. Torres-Arias, H. Afzali, T. K. Kuppusamy, R. Curtmola, and J. Cappos, "in-toto: Providing farm-to-table guarantees for bits and bytes," in Proc. 28th USENIX Security Symposium, 2019, pp. 1393-1410.

[17] Tekton Project, "Tekton Chains: Supply chain security for Tekton Pipelines," GitHub repository tektoncd/chains, 2021.

[18] M. Meli, M. R. McNiece, and B. Reaves, "How bad can it git? Characterizing secret leakage in public GitHub repositories," in Proc. Network and Distributed System Security Symposium (NDSS), 2019.

[19] The Kubernetes Authors, "Kubernetes documentation: Secrets, Service Accounts and Dynamic Admission Control," kubernetes.io, 2021.

[20] M. Souppaya, J. Morello, and K. Scarfone, "Application container security guide," NIST Special Publication 800-190, Sep. 2017.

[21] J. Humble and D. Farley, Continuous Delivery: Reliable Software Releases through Build, Test, and Deployment Automation. Upper Saddle River, NJ, USA: Addison-Wesley, 2010.

[22] N. Forsgren, J. Humble, and G. Kim, Accelerate: The Science of Lean Software and DevOps. Portland, OR, USA: IT Revolution Press, 2018.

[23] PCI Security Standards Council, "Payment Card Industry (PCI) Data Security Standard: Requirements and security assessment procedures," v3.2.1, May 2018.

[24] D. Dodson, M. Souppaya, and K. Scarfone, "Mitigating the risk of software vulnerabilities by adopting a Secure Software Development Framework (SSDF)," NIST Cybersecurity White Paper, Apr. 2020.

[25] CNCF Security Technical Advisory Group, "Cloud native security whitepaper," v1.0, Cloud Native Computing Foundation, Nov. 2020.

[26] R. Chandramouli, "Security strategies for microservices-based application systems," NIST Special Publication 800-204, Aug. 2019.

[27] ISO/IEC 5962:2021, "Information technology: SPDX Specification V2.2.1," International Organization for Standardization, 2021.

[28] Open Policy Agent Project, "OPA documentation: Policy language (Rego) and Conftest," openpolicyagent.org, 2021.

Downloads

Published

2022-11-20

How to Cite

Supply-Chain-Aware CI/CD for Regulated Enterprises: Integrating Artifact Signing, Secret Injection and Promotion Gates in Kubernetes-Native Pipelines. (2022). International Journal of Computer Technology and Electronics Communication, 5(6), 16275-16285. https://doi.org/10.15680/IJCTECE.2022.0506028

Most read articles by the same author(s)