Skip to content
About

Prerequisites and glossary

You need basic Git and container knowledge to follow the handbook: a commit identifies repository content, a Dockerfile describes image construction, an image contains filesystem layers and runtime configuration, and Kubernetes creates Pods from desired state. Cloud expertise is unnecessary for reading. Local checks and live reproduction have different prerequisites.

For local inspection, use Git and a text editor; Helm is useful for rendering the workload chart. Python with PyYAML and JMESPath runs the historical policy regression checks. Terraform initialization downloads providers even with its backend disabled, so it is a local configuration check with network dependencies, not a cloud deployment. See safe local inspection.

Live reproduction additionally requires an owned billed GCP project, permission to establish federation and IAM, an intentionally selected state bucket, access to the chosen Kubernetes endpoint, and an owned repository/ref trust contract. Never replace those inputs with identifiers copied from historical evidence. See reproduction prerequisites.

Term and searchable synonym Meaning in this project Read next
Digest; image hash; immutable image identifier A sha256: identifier of the image manifest used to bind the scan, signature, statements, and workload selection to the same artifact. Digests
Tag; image label A registry name such as a Git SHA that points to an artifact. It is a useful lookup label, while the workload selects the digest. Build
Signature; Cosign signature A cryptographic statement bound to an image digest and verified against the expected certificate identity and issuer. Signing
Attestation; signed statement A signed envelope carrying a typed claim about the artifact, such as an SBOM or provenance predicate. Claims
SBOM; software bill of materials A package inventory. The release workflow generates SPDX JSON with Syft from the final image; package completeness and safety are separate questions. Attestations
SPDX; Software Package Data Exchange The SBOM format and attestation type required by CI and admission. Verification contract
Provenance; build origin Workflow-generated claims about source, builder, and invocation. A SLSA-shaped predicate alone does not establish a SLSA assurance level. Attestations
SLSA; Supply-chain Levels for Software Artifacts A supply-chain assurance framework. This baseline emits the v0.2 provenance predicate; this handbook makes no level certification claim. Claims
Term and searchable synonym Meaning in this project Read next
OIDC; OpenID Connect; identity token The GitHub-issued identity mechanism used by distinct cloud federation and Sigstore signing exchanges. Identity
WIF; Workload Identity Federation The GCP trust configuration that lets GitHub impersonate a service account using short-lived credentials. Cloud exchange
GSA / KSA; Google / Kubernetes ServiceAccount Different identity objects. Kyverno’s KSA is bound to a GSA with reader access to registry content. Wiring
GAR; Google Artifact Registry The image repository and separate Cosign metadata repository in this baseline. Digests
GKE; Google Kubernetes Engine The cluster hosting the historical workload and security controllers. Private nodes do not imply a private-only API endpoint. Infrastructure
GitOps; reconciliation; desired state Argo CD watches a reviewed Git definition and attempts to make cluster state match it. Promotion
Admission; webhook; enforcement The Kubernetes API boundary where Kyverno evaluates in-scope image requirements before accepting a request. Admission
Enforce; deny Policy violations are configured to reject matching admission requests. This label alone does not prove outage behavior. Scope
Runtime detection; Falco; eBPF Observing selected process/system activity after admission. A detected event is not a prevented event. Runtime

The source workflow and admission policy are the authority for how these terms connect here. Start with the release journey when the vocabulary feels familiar.