Skip to main content

Platform Admission and Exceptions

Enforce image, provenance, privilege, identity, and network policy. Process one justified exception with owner, compensation, evidence, and automatic expiry.

Required evidence

Submit threat paths, machine-readable inventory and provenance, verified identities and digests, policy decisions, negative tampering test, exception lifecycle, recovery evidence, and residual risk. A badge or scanner report without verification does not pass.

Oral defense

Trace running bytes to reviewed source, demonstrate a failed tampering attempt, explain the verifier trust root, and execute revocation plus clean rebuild.

Source backbone

Use SLSA, NIST SSDF, Sigstore, Kubernetes admission documentation, and Building Secure and Reliable Systems.