Build Secure Multi-Arch Images, Sign, Scan & Deploy with GitHub Actions + Cosign + Trivy

Job Overview

Budget

$1,450.00

Level

MidLevel

Location

United States

Job Posted

26 Sep, 2025

Category

DevOps

Total Proposals

0

Job Description

Strategic Gap

Your start-up has 12 micro-services (Node, Python, Go) built by different teams. Images are >1 GB, sometimes root-user, no SBOM, no signature, and vulnerabilities are discovered post-deployment. Investors now require software supply-chain compliance ( NTIA SBOM, SLSA L3 roadmap). You need a standardized, secure, CI-native container factory that developers love and auditors accept.

Compliance & Performance Targets

  • Image size ≤ 120 MB (from ~1.2 GB).
  • Zero CVE > HIGH in base images; <5 MEDIUM in final layer.
  • Signed images ( Cosign ) + SBOM ( Syft ) attached in registry.
  • Multi-arch ( amd64 + arm64 ) for Apple M1 laptops and Graviton savings.
  • Non-root user, read-only root filesystem, distroless where possible.

 End-to-End Scope I Will Deliver

  • Base-Line Assessment
    • Dockerfile audit matrix: image size, layer count, USER directive, package manager.
    • Trivy scan baseline JSON → CVE count per severity.
  • Golden Dockerfile Templates
    • Multi-stage pattern: builder (compile) → tester (unit) → runtime (distroless or alpine).
    • ARG targets for amd64/arm64 (TARGETARCH, BUILDPLATFORM).
    • USER 65534 (non-root) + HEALTHCHECK + LABEL metadata (version, commit SHA, build date).
  • CI/CD Pipeline (GitHub Actions)
    • Matrix strategy builds both architectures in parallel ( QEMU + Docker Buildx ).
    • Cache mounts (type=cache,target=/root/.cache) → build time −40 %.
    • Trivy scan gates: job fails if CVE > HIGH; SARIF uploaded to GitHub Security tab.
    • Cosign keyless signing ( OIDC federated ) → attestation stored in GHCR.
    • Syft generates SPDX JSON SBOM → attached to OCI manifest.
  • Registry & Signing Setup
    • GitHub Container Registry ( GHCR ) enabled for organisation.
    • OIDC trust between GitHub and GHCR → no long-lived passwords.
    • Cosign public key uploaded to .well-known/cosign.pub for manual verification.
  • Supply-Chain Verification
    • Policy-controller ( Kubernetes optional ) validates signature + SBOM before admission.
    • SLSA provenance generated ( GitHub native ) → L2 achieved ( L3 roadmap document).
  • Developer Experience & Rollout
    • README template: how to build, scan, sign locally.
    • Makefile shortcuts: make build, make scan, make sign.
    • Brown-bag session ( 45 min Zoom ) recording for engineering teams.
  • Enterprise-Grade Deliverables
    • Golden Dockerfile templates ( Node, Python, Go ) + GitHub Actions workflow YAML.
    • Registry ( GHCR ) organisation setup + OIDC federation Terraform.
    • SBOM & attestation examples ( JSON ) + verification script (cosign verify …).
    • Compliance evidence: Trivy scan, SARIF, SLSA provenance JSON files signed.

Why a Mid-Level Specialist is Critical

  • Cosign & Trivy deep knowledge → avoids supply-chain attacks.
  • Multi-arch + QEMU experience → prevents Graviton surprises.
  • 30-day post-delivery support ( shared Slack channel ) for new micro-services onboarding.

Skills

  • Containerization technologies (e.g., Docker, Kubernetes)

Tags

Containerization technologies (e.g., Docker, Kubernetes)

Author Spotlight

Jessica Williams

Jessica Williams

Client

No description available.

Related Jobs

1 year ago Senior
$70.00 Hourly

We are seeking a Security Information and Event Management (SIEM) Analyst to set up and manage SIEM solutions for compre...

Log aggregation and analysis
View More
1 year ago MidLevel
$70.00 Hourly

We are seeking a Container Security Specialist to secure our containerized applications, ensuring each component is isol...

Containerization technologies (e.g., Docker, Kubernetes)
View More
1 year ago Senior
$75.00 Hourly

We are looking for a DevSecOps Engineer to integrate security into every stage of our software development lifecycle (SD...

CI/CD security and best practices
View More
1 year ago Junior
$75.00 Hourly

We are hiring a Microservices Security Consultant to implement and manage security protocols for our microservices archi...

Microservices security
View More
Jessica Williams

Jessica Williams

United States


Member Since
Aug 05, 2025
Total Created Jobs
4