Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Secure Continuous Delivery on Google Cloud

You're reading from  Secure Continuous Delivery on Google Cloud

Product type Book
Published in Apr 2024
Publisher Packt
ISBN-13 9781805129288
Pages 304 pages
Edition 1st Edition
Languages
Concepts
Authors (3):
Giovanni Galloro Giovanni Galloro
Profile icon Giovanni Galloro
Nathaniel Avery Nathaniel Avery
Profile icon Nathaniel Avery
David Dorbin David Dorbin
Profile icon David Dorbin
View More author details

Table of Contents (19) Chapters

Preface 1. Part 1:Introduction and Code Your Application
2. Chapter 1: Introducing Continuous Delivery and Software Supply Chain Security 3. Chapter 2: Using Skaffold for Development, Build, and Deploy 4. Chapter 3: Developing and Testing with Cloud Code 5. Chapter 4: Securing Your Code with Cloud Workstations 6. Part 2: Build and Package Your Application
7. Chapter 5: Automating Continuous Integration with Cloud Build 8. Chapter 6: Securely Store Your Software on Artifact Registry 9. Part 3: Deploy and Run Your Application
10. Chapter 7: Exploring Runtimes – GKE, GKE Enterprise, and Cloud Run 11. Chapter 8: Automating Software Delivery Using Cloud Deploy 12. Chapter 9: Securing Your Runtimes with Binary Authorization 13. Part 4: Hands-On Secure Pipeline Delivery and Looking Forward
14. Chapter 10: Demonstrating an End-to-End Software Delivery Pipeline 15. Chapter 11: Integrating with Your Organization’s Workflows 16. Chapter 12: Diving into Best Practices and Trends in Continuous Delivery 17. Index 18. Other Books You May Enjoy

Setting up Binary Authorization

Binary Authorization evaluates containerized workloads. It requires the container to be signed using a compliant key. We can sign the container images using either a Google-managed key or one created with Google’s CMEK. Also, the image must comply with a customer-defined policy.

This exercise will walk you through the steps of setting up the environment and then signing the container.

Here is an overview of the process:

  1. Environment preparation:
    1. Create a key with CMEK.
    2. Create a Binary Authorization policy.
    3. Enable the policy.
  2. Container preparation:
    1. Create a container.
    2. Sign the container.
    3. Deploy the container.

Let’s get started.

Creating a CMEK

Encryption keys are fundamental to the security of your applications and the systems you use to deliver those applications. CMEKs give you control over the keys you use to keep your customers’ data secure.

Binary Authorization uses either a customer-managed key or...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime}