A software bill of materials lists components associated with an artifact. Build provenance records how an artifact was produced, including the builder and source inputs. Neither file makes a release safe merely by existing. A deployment policy must verify the attestation against a trusted identity and compare the artifact digest with the object being admitted.
Software supply chain: SBOM and provenance at admission
Operational decision
For a reconciliation worker, generate an SBOM when the image is built, attach provenance to the exact digest, scan the component inventory against current advisories, and verify the builder identity before promotion. Decide what happens when a dependency has no known version or a scan service is unavailable; silent success is not a policy. Allow a time-limited exception only with an owner, affected digest, reason, and expiry. The YAML sketch is an internal release policy, not a standard admission-controller API. A real implementation should verify signatures or trusted attestations cryptographically and reject a digest with no matching statement. Re-scan retained images as advisory data changes; an image that passed last week can become vulnerable without being rebuilt.
service: reconciliation-worker
artifactDigest: sha256:47b22c901a19
requiredBuilder: isolated-release-builder
requireProvenance: true
requireSbom: true
unknownScanResult: hold
exceptionExpires: nullCost and verification
SBOM generation, signing, verification, and repeated scanning add build time and storage. An SBOM may omit runtime-installed components or misidentify a package; validate inventory quality before using it as a hard gate. Provenance ties an image to a builder but does not prove its source code is free of defects. The shortened digest is illustrative and must become a full registry digest. Keep trusted builder identifiers and policy changes under review, because weakening either defeats the check.
Common Mistakes
- Do not treat an SBOM as a vulnerability-free certificate.
- Do not accept provenance without matching its artifact digest.
- Do not turn scanner outages into automatic approvals.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Immutable artifacts and release provenance
- Container builds: small runtime, explicit privilege
- CI runner isolation: treat repository code as untrusted
Advanced follow-up
Advanced follow-up
Advanced follow-up
Advanced follow-up
- Reproducible builds: investigate why equal inputs produce different bytes
- Tested artifact identity: deploy the bytes that passed
