Container Image Hardening Pipeline Vulnerability Scanning Policy Gates and Runtime Efficiency in Production Kubernetes

Fuente: Zenodo
Saved in:
Bibliographic Details
Main Author: Junaid, Ehtesham
Format: Recurso digital
Published: Zenodo 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866901351352500224
author Junaid, Ehtesham
author_facet Junaid, Ehtesham
contents <p>The adoption of containerized applications and Kubernetes has improved scalability but introduced significant security challenges such as vulnerable images and runtime risks. This study proposes a DevSecOps-based container image hardening pipeline that integrates vulnerability scanning, policy-as-code enforcement, and runtime monitoring within a Kubernetes environment. A risk-scoring mechanism is used to evaluate container images, and deployment decisions are enforced through automated policy gates. Experimental results show that the proposed system significantly reduces the deployment of high-risk images and improves overall security posture. However, it introduces moderate overhead in CPU usage, memory consumption, and deployment latency, indicating a security–performance trade-off. The study demonstrates that an integrated security pipeline is more effective than isolated security mechanisms for secure Kubernetes deployments.</p> <p> </p>
format Recurso digital
id zenodo_https___doi_org_10_5281_zenodo_20026854
institution Zenodo
language
publishDate 2026
publisher Zenodo
record_format zenodo
spellingShingle Container Image Hardening Pipeline Vulnerability Scanning Policy Gates and Runtime Efficiency in Production Kubernetes
Junaid, Ehtesham
Container Security
Kubernetes
DevSecOps
Vulnerability Scanning
Policy Enforcement
Runtime Monitoring
CI/CD
Cloud Security
<p>The adoption of containerized applications and Kubernetes has improved scalability but introduced significant security challenges such as vulnerable images and runtime risks. This study proposes a DevSecOps-based container image hardening pipeline that integrates vulnerability scanning, policy-as-code enforcement, and runtime monitoring within a Kubernetes environment. A risk-scoring mechanism is used to evaluate container images, and deployment decisions are enforced through automated policy gates. Experimental results show that the proposed system significantly reduces the deployment of high-risk images and improves overall security posture. However, it introduces moderate overhead in CPU usage, memory consumption, and deployment latency, indicating a security–performance trade-off. The study demonstrates that an integrated security pipeline is more effective than isolated security mechanisms for secure Kubernetes deployments.</p> <p> </p>
title Container Image Hardening Pipeline Vulnerability Scanning Policy Gates and Runtime Efficiency in Production Kubernetes
topic Container Security
Kubernetes
DevSecOps
Vulnerability Scanning
Policy Enforcement
Runtime Monitoring
CI/CD
Cloud Security
url https://doi.org/10.5281/zenodo.20026854