Skip to lesson
supraj.dev THE ENGINEERING HANDBOOKS
LEARN / BUILD / VERIFY2026 edition · checked 06 Oct

CHAPTER 26 / 30 · Build with evidence

Image identity and software supply chain

Tie a workload to a reviewed artifact and keep scanning claims within their evidence.

4 min read + practiceWorked exerciseInterview practice

The mechanism

An image tag is a name that may be moved; a digest identifies particular content. A reviewed digest improves reproducibility, but it does not establish that the content is safe or that the application behaves correctly. Provenance, dependency review and runtime controls answer different questions.

Image pulling also has prerequisites: registry reachability, authentication, platform architecture and configured policy. A Pod that cannot pull an image has not yet tested the application process. Separate supply-chain verification from runtime diagnosis.

For ParcelOps, record the source revision, build process, artifact digest, scan scope and approval. Do not claim a clean scan proves absence of vulnerabilities. A scanner’s database, configuration and date affect what it can detect.

Source revision
Reviewed build
Artifact digest
Admission + runtime evidence

Worked example

This is a release evidence template, not a real build attestation. Null values remain null until observed. The handbook supplies no invented image digest or vulnerability result.

{"application":"parcelops","source_revision":null,
 "builder_identity":null,"image_digest":null,"platform":null,
 "scan":{"tool":null,"database_date":null,"result":"not_run"},
 "provenance_verification":"not_run","approval":"pending"}

Practice: predict, inspect, explain

Offline exercise. Explain how a mutable tag could point to different content between review and rollout. Then identify which evidence a digest does provide and which it does not. Add a dependency vulnerability discovered after deployment and describe the update-and-retest workflow.

Expected observation: artifact identity makes investigation reproducible but does not eliminate patching or behavioral testing. Keep image pull credentials out of manifests committed to the site. Optional admission verification requires a real configured policy and compatible implementation, which are not installed by this book.

Troubleshooting and trade-offs

If a rollout uses unexpected code, compare the observed image identity with the reviewed release record. If pull fails, inspect reference, registry access and platform compatibility without exposing credentials. If a scan is old, update the evidence rather than presenting it as current. Do not substitute an unreviewed public image just to make a lab start.

Interview practice

What does a digest establish?

It identifies image content. It does not by itself prove trustworthy provenance, absence of vulnerabilities or application correctness.

Why record scanner metadata?

Findings depend on tool version, database freshness and scan configuration. Those details bound what the result means.

Completion check

Create a release record with honest unknowns and explain the difference between identity, provenance and safety.

Sources and version notes

Baseline checked 6 October 2026: the official release page lists Kubernetes 1.37.1. Verify your cluster and distribution prerequisites. All manifests are offline teaching examples; no cluster mutations or cloud resources are executed by this handbook.

YOUR NEXT STEP

Make the understanding yours.

Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.

Self-assessed reading progress. This does not certify that a lab ran or a system is secure.