Container Image Hardening Pipeline Vulnerability Scanning Policy Gates and Runtime Efficiency in Production Kubernetes
Fuente:
Zenodo
Saved in:
| Main Author: | |
|---|---|
| Format: | Recurso digital |
| Published: |
Zenodo
2026
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866901351352500224 |
|---|---|
| author | Junaid, Ehtesham |
| author_facet | Junaid, Ehtesham |
| contents | <p>The adoption of containerized applications and Kubernetes has improved scalability but introduced significant security challenges such as vulnerable images and runtime risks. This study proposes a DevSecOps-based container image hardening pipeline that integrates vulnerability scanning, policy-as-code enforcement, and runtime monitoring within a Kubernetes environment. A risk-scoring mechanism is used to evaluate container images, and deployment decisions are enforced through automated policy gates. Experimental results show that the proposed system significantly reduces the deployment of high-risk images and improves overall security posture. However, it introduces moderate overhead in CPU usage, memory consumption, and deployment latency, indicating a security–performance trade-off. The study demonstrates that an integrated security pipeline is more effective than isolated security mechanisms for secure Kubernetes deployments.</p> <p> </p> |
| format | Recurso digital |
| id | zenodo_https___doi_org_10_5281_zenodo_20026854 |
| institution | Zenodo |
| language | |
| publishDate | 2026 |
| publisher | Zenodo |
| record_format | zenodo |
| spellingShingle | Container Image Hardening Pipeline Vulnerability Scanning Policy Gates and Runtime Efficiency in Production Kubernetes Junaid, Ehtesham Container Security Kubernetes DevSecOps Vulnerability Scanning Policy Enforcement Runtime Monitoring CI/CD Cloud Security <p>The adoption of containerized applications and Kubernetes has improved scalability but introduced significant security challenges such as vulnerable images and runtime risks. This study proposes a DevSecOps-based container image hardening pipeline that integrates vulnerability scanning, policy-as-code enforcement, and runtime monitoring within a Kubernetes environment. A risk-scoring mechanism is used to evaluate container images, and deployment decisions are enforced through automated policy gates. Experimental results show that the proposed system significantly reduces the deployment of high-risk images and improves overall security posture. However, it introduces moderate overhead in CPU usage, memory consumption, and deployment latency, indicating a security–performance trade-off. The study demonstrates that an integrated security pipeline is more effective than isolated security mechanisms for secure Kubernetes deployments.</p> <p> </p> |
| title | Container Image Hardening Pipeline Vulnerability Scanning Policy Gates and Runtime Efficiency in Production Kubernetes |
| topic | Container Security Kubernetes DevSecOps Vulnerability Scanning Policy Enforcement Runtime Monitoring CI/CD Cloud Security |
| url | https://doi.org/10.5281/zenodo.20026854 |