implementing-gcp-binary-authorization skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Implements GCP Binary Authorization end to end, including creating KMS-backed attestors, Container Analysis notes, deploy-time policies, and signing image attestations, so that only trusted, verified images deploy to GKE and Cloud Run. Use when enforcing container supply-chain integrity or deploy-time attestation checks on GCP. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/implementing-gcp-binary-authorization/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-gcp-binary-authorization, or copy the skill folder into ~/.claude/skills/implementing-gcp-binary-authorization/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-gcp-binary-authorization/SKILL.md

SKILL.md (verbatim)

name: implementing-gcp-binary-authorization
description: Implements GCP Binary Authorization end to end, including creating KMS-backed attestors, Container Analysis notes, deploy-time policies, and signing image attestations, so that only trusted, verified images deploy to GKE and Cloud Run. Use when enforcing container supply-chain integrity or deploy-time attestation checks on GCP.
domain: cybersecurity
subdomain: cloud-security
tags:
- gcp
- binary-authorization
- container-security
- supply-chain
- gke
- cloud-run
- attestation
- software-integrity
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.IR-01
- ID.AM-08
- GV.SC-06
- DE.CM-01
mitre_attack:
- T1078.004
- T1530
- T1537
- T1580
- T1610

Implementing GCP Binary Authorization

Overview

Binary Authorization is a Google Cloud deploy-time security control that ensures only trusted container images are deployed on GKE or Cloud Run. It works through a policy-based model where images must have cryptographic attestations confirming they passed predefined requirements such as vulnerability scans, code reviews, or build pipeline verification. Continuous validation (CV) monitors running pods against policies and logs violations.

When to Use

  • When deploying or configuring implementing gcp binary authorization capabilities in your environment
  • When establishing security controls aligned to compliance requirements
  • When building or improving security architecture for this domain
  • When conducting security assessments that require this implementation

Prerequisites

  • GCP project with Binary Authorization API enabled
  • GKE cluster or Cloud Run service
  • Container Analysis API enabled
  • KMS keys for attestation signing
  • Cloud Build or external CI/CD pipeline

Enable Binary Authorization

# Enable required APIs
gcloud services enable binaryauthorization.googleapis.com
gcloud services enable containeranalysis.googleapis.com
gcloud services enable container.googleapis.com

# Enable Binary Authorization on GKE cluster
gcloud container clusters update CLUSTER_NAME \
  --enable-binauthz \
  --zone us-central1-a

Create Attestor

Create a KMS key for signing

# Create keyring
gcloud kms keyrings create binauthz-keyring \
  --location global

# Create signing key
gcloud kms keys create attestor-key \
  --keyring binauthz-keyring \
  --location global \
  --algorithm ec-sign-p256-sha256 \
  --purpose asymmetric-signing

Create Container Analysis note

cat > /tmp/note.json << 'EOF'
{
  "attestation": {
    "hint": {
      "humanReadableName": "Production Build Attestor"
    }
  }
}
EOF

curl -X POST \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $(gcloud auth print-access-token)" \
  "https://containeranalysis.googleapis.com/v1/projects/PROJECT_ID/notes/?noteId=prod-build-note" \
  -d @/tmp/note.json

Create the attestor

gcloud container binauthz attestors create prod-build-attestor \
  --attestation-authority-note=prod-build-note \
  --attestation-authority-note-project=PROJECT_ID

# Add KMS key to attestor
gcloud container binauthz attestors public-keys add \
  --attestor=prod-build-attestor \
  --keyversion-project=PROJECT_ID \
  --keyversion-location=global \
  --keyversion-keyring=binauthz-keyring \
  --keyversion-key=attestor-key \
  --keyversion=1

Configure Policy

Default deny-all policy

# binauthz-policy.yaml
admissionWhitelistPatterns:
  - namePattern: "gcr.io/google_containers/*"
  - namePattern: "gcr.io/google-containers/*"
  - namePattern: "k8s.gcr.io/**"
  - namePattern: "gke.gcr.io/**"
  - namePattern: "gcr.io/stackdriver-agents/*"
defaultAdmissionRule:
  evaluationMode: REQUIRE_ATTESTATION
  enforcementMode: ENFORCED_BLOCK_AND_AUDIT_LOG
  requireAttestationsBy:
    - projects/PROJECT_ID/attestors/prod-build-attestor
globalPolicyEvaluationMode: ENABLE
gcloud container binauthz policy import binauthz-policy.yaml

Per-cluster rules

admissionWhitelistPatterns:
  - namePattern: "gcr.io/google_containers/*"
clusterAdmissionRules:
  us-central1-a.production-cluster:
    evaluationMode: REQUIRE_ATTESTATION
    enforcementMode: ENFORCED_BLOCK_AND_AUDIT_LOG
    requireAttestationsBy:
      - projects/PROJECT_ID/attestors/prod-build-attestor
  us-central1-a.staging-cluster:
    evaluationMode: ALWAYS_ALLOW
    enforcementMode: DRYRUN_AUDIT_LOG_ONLY
defaultAdmissionRule:
  evaluationMode: ALWAYS_DENY
  enforcementMode: ENFORCED_BLOCK_AND_AUDIT_LOG

Create Attestations

Attest an image after successful build

# Get image digest
IMAGE_DIGEST=$(gcloud container images describe \
  gcr.io/PROJECT_ID/my-app:latest \
  --format='get(image_summary.digest)')

# Create attestation
gcloud container binauthz attestations sign-and-create \
  --artifact-url="gcr.io/PROJECT_ID/my-app@${IMAGE_DIGEST}" \
  --attestor="prod-build-attestor" \
  --attestor-project="PROJECT_ID" \
  --keyversion-project="PROJECT_ID" \
  --keyversion-location="global" \
  --keyversion-keyring="binauthz-keyring" \
  --keyversion-key="attestor-key" \
  --keyversion="1"

Cloud Build integration

# cloudbuild.yaml
steps:
  - name: 'gcr.io/cloud-builders/docker'
    args: ['build', '-t', 'gcr.io/$PROJECT_ID/my-app:$SHORT_SHA', '.']

  - name: 'gcr.io/cloud-builders/docker'
    args: ['push', 'gcr.io/$PROJECT_ID/my-app:$SHORT_SHA']

  # Vulnerability scanning
  - name: 'gcr.io/cloud-builders/gcloud'
    entrypoint: 'bash'
    args:
      - '-c'
      - |
        gcloud artifacts docker images scan \
          gcr.io/$PROJECT_ID/my-app:$SHORT_SHA \
          --format='value(response.scan)'

  # Create attestation after successful scan
  - name: 'gcr.io/cloud-builders/gcloud'
    entrypoint: 'bash'
    args:
      - '-c'
      - |
        IMAGE_DIGEST=$(gcloud container images describe \
          gcr.io/$PROJECT_ID/my-app:$SHORT_SHA \
          --format='get(image_summary.digest)')
        gcloud container binauthz attestations sign-and-create \
          --artifact-url="gcr.io/$PROJECT_ID/my-app@$${IMAGE_DIGEST}" \
          --attestor="prod-build-attestor" \
          --attestor-project="$PROJECT_ID" \
          --keyversion-project="$PROJECT_ID" \
          --keyversion-location="global" \
          --keyversion-keyring="binauthz-keyring" \
          --keyversion-key="attestor-key" \
          --keyversion="1"

Continuous Validation

# Enable CV on a GKE cluster
gcloud container clusters update CLUSTER_NAME \
  --enable-binauthz-monitoring \
  --zone us-central1-a

Monitor CV violations in Cloud Logging

resource.type="k8s_cluster"
logName="projects/PROJECT_ID/logs/binaryauthorization.googleapis.com%2Fcontinuous_validation"

Verification and Testing

Test deployment of unattested image

# This should be blocked
kubectl run test-unapproved \
  --image=docker.io/library/nginx:latest

# Verify the pod was denied
kubectl get events --field-selector reason=FailedCreate

Verify attestation exists

gcloud container binauthz attestations list \
  --attestor=prod-build-attestor \
  --attestor-project=PROJECT_ID

Break-Glass Override

For emergency deployments bypassing Binary Authorization:

apiVersion: v1
kind: Pod
metadata:
  name: emergency-pod
  labels:
    image-policy.k8s.io/break-glass: "true"
  annotations:
    alpha.image-policy.k8s.io/break-glass: "Emergency deployment - ticket INC-12345"
spec:
  containers:
    - name: emergency
      image: gcr.io/PROJECT_ID/emergency-fix:latest

References

Other files in this skill

assets/template.md (verbatim)

GCP Binary Authorization Implementation Template

Configuration

Setting Value
Project ID
GKE Cluster
Attestor Name
KMS Key Location
Policy Mode Enforce / Dry-Run

Attestor Checklist

  • KMS keyring and key created
  • Container Analysis note created
  • Attestor created and linked to note
  • Public key added to attestor
  • CI/CD pipeline creates attestations
  • Break-glass procedure documented

Policy Configuration

Rule Scope Mode Attestors Required
Default All clusters
Production prod-cluster
Staging staging-cluster

references/api-reference.md (verbatim)

API Reference: Implementing GCP Binary Authorization

gcloud CLI Commands

# Enable APIs
gcloud services enable binaryauthorization.googleapis.com containeranalysis.googleapis.com

# Enable on GKE cluster
gcloud container clusters update CLUSTER --enable-binauthz --zone ZONE

# Export policy
gcloud container binauthz policy export --project PROJECT_ID

# Import policy
gcloud container binauthz policy import policy.yaml

# Create attestor
gcloud container binauthz attestors create ATTESTOR_NAME \
  --attestation-authority-note=NOTE_ID \
  --attestation-authority-note-project=PROJECT_ID

# Create attestation
gcloud container binauthz attestations sign-and-create \
  --artifact-url="gcr.io/PROJECT/IMAGE@DIGEST" \
  --attestor="ATTESTOR" --attestor-project="PROJECT" \
  --keyversion-project=PROJECT --keyversion-location=global \
  --keyversion-keyring=KEYRING --keyversion-key=KEY --keyversion=1

Policy Structure

Field Values Description
evaluationMode ALWAYS_ALLOW, ALWAYS_DENY, REQUIRE_ATTESTATION How images are evaluated
enforcementMode ENFORCED_BLOCK_AND_AUDIT_LOG, DRYRUN_AUDIT_LOG_ONLY Block or audit-only
globalPolicyEvaluationMode ENABLE, DISABLE Google-maintained system policy

Break-Glass Annotation

metadata:
  annotations:
    alpha.image-policy.k8s.io/break-glass: "Emergency - INC-12345"

Cloud Logging Filter (CV Violations)

resource.type="k8s_cluster"
logName="projects/PROJECT/logs/binaryauthorization.googleapis.com%2Fcontinuous_validation"

References

references/standards.md (verbatim)

Standards - GCP Binary Authorization

SLSA Framework Levels

  • SLSA 1: Documentation of build process
  • SLSA 2: Tamper resistance of build service
  • SLSA 3: Extra resistance to threats
  • SLSA 4: Highest levels of confidence and trust

NIST 800-53

  • SA-10: Developer Configuration Management
  • SA-12: Supply Chain Protection
  • SI-7: Software, Firmware, and Information Integrity

CIS GKE Benchmark

  • 6.10.4: Ensure Binary Authorization is enabled for GKE clusters

references/workflows.md (verbatim)

Workflows - GCP Binary Authorization

Attestation Pipeline

1. Developer pushes code
2. Cloud Build triggers container build
3. Vulnerability scan runs on built image
4. If scan passes → Create cryptographic attestation
5. Push attested image to registry
6. GKE validates attestation at deploy time
7. Continuous validation monitors running pods

Break-Glass Procedure

1. Emergency identified → Create incident ticket
2. Apply break-glass annotation to pod spec
3. Deploy with override documented
4. Alert security team of break-glass usage
5. Post-incident: Review and attest emergency image
6. Remove break-glass annotation

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.