FEATMATE
DevOps Fixed Price

Build Secure Multi-Arch Images, Sign, Scan & Deploy with GitHub Actions + Cosign + Trivy

Posted 11 months ago  ·  0 proposals


Budget

$1,450.00

Level

MidLevel

Location

United States

Posted

Sep 26, 2025

Proposals

0

Job Type

Fixed Price

Job Description

Strategic Gap

Your start-up has 12 micro-services (Node, Python, Go) built by different teams. Images are >1 GB, sometimes root-user, no SBOM, no signature, and vulnerabilities are discovered post-deployment. Investors now require software supply-chain compliance ( NTIA SBOM, SLSA L3 roadmap). You need a standardized, secure, CI-native container factory that developers love and auditors accept.

Compliance & Performance Targets

  • Image size ≤ 120 MB (from ~1.2 GB).
  • Zero CVE > HIGH in base images; <5 MEDIUM in final layer.
  • Signed images ( Cosign ) + SBOM ( Syft ) attached in registry.
  • Multi-arch ( amd64 + arm64 ) for Apple M1 laptops and Graviton savings.
  • Non-root user, read-only root filesystem, distroless where possible.

 End-to-End Scope I Will Deliver

  • Base-Line Assessment
    • Dockerfile audit matrix: image size, layer count, USER directive, package manager.
    • Trivy scan baseline JSON → CVE count per severity.
  • Golden Dockerfile Templates
    • Multi-stage pattern: builder (compile) → tester (unit) → runtime (distroless or alpine).
    • ARG targets for amd64/arm64 (TARGETARCH, BUILDPLATFORM).
    • USER 65534 (non-root) + HEALTHCHECK + LABEL metadata (version, commit SHA, build date).
  • CI/CD Pipeline (GitHub Actions)
    • Matrix strategy builds both architectures in parallel ( QEMU + Docker Buildx ).
    • Cache mounts (type=cache,target=/root/.cache) → build time −40 %.
    • Trivy scan gates: job fails if CVE > HIGH; SARIF uploaded to GitHub Security tab.
    • Cosign keyless signing ( OIDC federated ) → attestation stored in GHCR.
    • Syft generates SPDX JSON SBOM → attached to OCI manifest.
  • Registry & Signing Setup
    • GitHub Container Registry ( GHCR ) enabled for organisation.
    • OIDC trust between GitHub and GHCR → no long-lived passwords.
    • Cosign public key uploaded to .well-known/cosign.pub for manual verification.
  • Supply-Chain Verification
    • Policy-controller ( Kubernetes optional ) validates signature + SBOM before admission.
    • SLSA provenance generated ( GitHub native ) → L2 achieved ( L3 roadmap document).
  • Developer Experience & Rollout
    • README template: how to build, scan, sign locally.
    • Makefile shortcuts: make build, make scan, make sign.
    • Brown-bag session ( 45 min Zoom ) recording for engineering teams.
  • Enterprise-Grade Deliverables
    • Golden Dockerfile templates ( Node, Python, Go ) + GitHub Actions workflow YAML.
    • Registry ( GHCR ) organisation setup + OIDC federation Terraform.
    • SBOM & attestation examples ( JSON ) + verification script (cosign verify …).
    • Compliance evidence: Trivy scan, SARIF, SLSA provenance JSON files signed.

Why a Mid-Level Specialist is Critical

  • Cosign & Trivy deep knowledge → avoids supply-chain attacks.
  • Multi-arch + QEMU experience → prevents Graviton surprises.
  • 30-day post-delivery support ( shared Slack channel ) for new micro-services onboarding.
About the Client
Jessica Williams

Jessica Williams

Client  ·  United States

Related Jobs
$70.00 Hourly Senior 1 year ago

We are seeking a Security Information and Event Management (SIEM) Analyst to set up and manage SIEM...

Log aggregation and analysis
View Job →
$70.00 Hourly MidLevel 1 year ago

We are seeking a Container Security Specialist to secure our containerized applications, ensuring ea...

Containerization technologies (e.g., Docker, Kubernetes)
View Job →
$75.00 Hourly Senior 1 year ago

We are looking for a DevSecOps Engineer to integrate security into every stage of our software devel...

CI/CD security and best practices
View Job →
$75.00 Hourly Junior 1 year ago

We are hiring a Microservices Security Consultant to implement and manage security protocols for our...

Microservices security
View Job →

Login as a freelancer to apply

Jessica Williams

Jessica Williams

Offline

United States


Member Since
Aug 2025
Total Jobs Posted
4