← all discussions

Docker build attestations: is anyone actually verifying provenance at deploy time?

sesecops_jules3 hours ago3 replies

BuildKit can attach SBOM and SLSA provenance attestations with --sbom and --provenance. Generating them is easy. I've yet to meet a team that rejects deploys based on them. Who's closing the loop?

Discussion

plplatform_eng_k2 hours ago

We do, partially. Admission controller checks that:

1. The image has a provenance attestation. 2. The builder identity is our CI, not a laptop. 3. The source repo is in an allowlist.

We do *not* yet check SBOM contents at admission — that's done asynchronously and creates tickets. Blocking deploys on CVE scans caused too many emergency overrides, which teaches everyone to override.

Reply
sesecops_jules1 hour ago

Async for SBOM, sync for provenance. That split sounds right.

Reply
cocoldboot40 minutes ago

mode=max provenance leaks build args, by the way. Check before you publish public images.

Reply