A signature or attestation can be attached to an image digest, but a workload may specify a mutable tag, a multi-platform index, or an image rewritten by an admission mutator. The verifier must define which resolved subject it checks and which builder, repository, and evidence predicates it accepts. Admission is also an availability dependency: verifier timeout, registry outage, and stale trust material can stop new workloads if failure behavior is not rehearsed.
Admission verification: compare the running image with approved evidence
Operational decision
A parcel API is deployed to a test cluster by digest. Configure a verification policy that accepts only the reviewed builder and provenance subject for the exact image being admitted. Test a signed image from an unapproved workflow, a valid statement attached to a different digest, a missing SBOM, and a moved tag; each must receive the intended result. For an image index, verify the index and required platform child manifests according to the policy's declared scope. Run the verifier in audit or warning mode against current workloads before enforcing denial, then measure latency and false denials. Simulate a registry timeout and a verifier outage to choose a failure policy consistent with the service's recovery objective; document a narrow emergency path with an expiry and audit record. A policy that rejects all replacement Pods during a verifier outage can turn a single dependency fault into a service outage. Conversely, silently allowing every image on timeout removes the security boundary. Capture the final admitted image reference and runtime image ID after the Pod starts to detect resolution or mutation differences.
Parcel admission matrix
Approved digest and builder: allow
Unapproved builder with valid signature: deny
Statement for another digest: deny
Required SBOM missing: deny or reviewed exception
Registry or verifier timeout: tested failure behavior
Runtime image ID: matches admitted subjectCost and verification
Verification adds registry lookups, signature work, and admission latency to each relevant workload creation. Cache by immutable digest with bounded freshness rather than by tag; a cache keyed only by name can reuse a verdict after the tag moves. Measure p95 admission latency, timeout rate, false denials, bypass use, and Pods whose runtime digest differs from the reviewed subject. Security policy and recovery availability must be tested together.
Common Mistakes
- Do not verify a tag once and assume it remains on the same bytes.
- Do not accept a valid attestation for a different subject digest.
- Do not enforce a gate before testing verifier and registry outages.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Kubernetes admission policy: reject an unsafe workload before scheduling
- Admission webhook outage: choose a deliberate failure path
- Build provenance: verify who asserted how the artifact was made
- Signature trust rollover: rotate verification roots without disabling admission
