Attestkeep 1.0 Launches as Kubernetes Admission Webhook with Compliance Evidence Engine
Attestkeep, a validating admission webhook for Kubernetes, has reached version 1.0 following community feedback that directly shaped its development. The tool reviews every pod creation and update against a policy covering image tags, registry allow-lists, vulnerability thresholds, cosign signatures, and workload hardening checks, logging each decision to a tamper-evident ledger. A key contribution from community member Vinh Nguyen led to the addition of an hourly sweep that reconciles running container image digests against the ledger, catching workloads that entered outside the webhook's watch. Further feedback addressed edge cases involving controller-less pods and static pods, which are now flagged as unmanaged rather than silently mishandled. The ledger records both allowed and denied decisions, and operators can generate signed compliance evidence packages mapped to frameworks such as SOC 2, CRA, and NIS2.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in