
12/1/2020
What this post added
This post details the implementation of Binary Authorization in Kubernetes using Google's Grafeas and Kritis, and introduces Voucher as the missing signing service component. Voucher allows for security checks on Docker images before signing them, supporting various checks like verifying image origin and vulnerability levels. It also details how Voucher integrates with build pipelines and metadata services, and its subsequent move into the Grafeas organization as a Google-provided service.