The Secure Way
Build and supply chain, the secure way
Kaniko, Chainguard and Wolfi images, vendoring, signing with cosign and admission that refuses the unsigned.
20 guides
- Argo CD hardening, the secure wayHarden Argo CD: disable the admin user, empty the default project, scope AppProjects to one repo and namespace, and write RBAC where a team can sync but not delete.
- Builds with no internet access, the secure waySplit builds into a fetch stage that locks and verifies inputs and a build stage with no internet route. Tested with pip wheels, Go vendoring and kaniko.
- Chainguard and Wolfi base images, the secure wayUse Chainguard images and Wolfi well: pin the free latest tag by digest, verify its signature, build in -dev, ship without a shell, read scans honestly.
- Containing a root Kaniko build, the secure wayKaniko needs root inside its container. How to drop it to five capabilities, cut its network and credentials, and keep a hostile Dockerfile off your nodes.
- Digest pinning in GitOps, the secure wayPin every image in your GitOps repository by sha256 digest with kustomize, keep the tag for humans, and fail CI when any rendered manifest has an unpinned image.
- Forgejo Actions runner isolation, the secure wayIsolate Forgejo Actions runners: no host label, no Docker socket in jobs, dropped capabilities and limits, one runner per trust level on its own VM.
- Git forge disaster recovery, the secure wayBack up a self-hosted Forgejo so you can really restore it: verified git bundles off the server, encrypted snapshots with the secrets, and restore drills.
- GitOps without circular dependencies, the secure wayYour GitOps tool deploys the Git server it reads from? Break the loops between Argo CD, the forge, the registry, secrets and SSO so a dead cluster can come back.
- Kaniko: building images without Docker, the secure wayBuild container images in CI with kaniko instead of the Docker socket: the maintained fork, a digest-pinned executor, reproducible builds, no push in PRs.
- Mirroring base images with a scan and a signature, the secure wayMirror upstream container images only after the upstream signature verifies and a grype scan passes; copy by digest and sign the mirrored digest.
- Offline cosign signing, the secure waySign release files and container images with a cosign key pair and no internet, no Fulcio and no Rekor, using cosign v3 signing configs, and verify them offline.
- Promotion workflows where CI can only write digests, the secure wayLet CI promote releases through GitOps without write access to anything else: digest-only commits, a required check that proves it, and staging before prod.
- Registry tags that never move, the secure wayMake container image tags immutable: what OCI registries promise, how Harbor, ECR and zot enforce it, and a tested zot policy where CI can push but never overwrite.
- Rolling out the Sigstore policy-controller, the secure wayEnforce signed images on Kubernetes with the Sigstore policy-controller without breaking the cluster: opt-in namespaces, warn mode, then enforce and deny.
- SAST and secret scanning in CI, the secure wayRun gitleaks over every commit, not just the working tree, and semgrep with your own rules as blocking CI checks, offline and with redacted findings.
- SBOMs and attestations with Syft and cosign, the secure wayGenerate an SBOM with Syft from the exact image digest, attach it as a signed in-toto attestation with cosign, and verify signer and content before you trust it.
- Self-hosting Forgejo, the secure wayHarden a self-hosted Forgejo: no open registration, login required, 2FA for all, no git hooks, SSRF limits on migrations and webhooks, and a locked-down container.
- Vendored Go modules and hashed Python requirements, the secure wayVendor Go modules and lock Python requirements with hashes so builds use only reviewed bytes, and add the CI check go build skips: re-vendor and diff.
- Vendoring CI actions at pinned SHAs, the secure wayStop running other people's latest code in CI: vendor Forgejo and GitHub actions into your own forge at a reviewed commit, pin full SHAs, and fail CI on any tag.
- Wolfi's split packages and the mistakes they cause, the secure wayOn Wolfi, apk add gnupg installs no gpg at all. How split packages work, how to find the package that ships a command, and how to keep images small and working.
T Academy
Every guide here is taught hands-on in H2-CSDE DevSecOps and Supply Chain: a real host in your browser, and every objective checked on the machine.
Start free