All projects
Case study 03 / 08Academic / Personal

Defensive CI/CD Pipeline for Docker Container Security

A security-integrated pipeline with a migration away from privileged Docker-in-Docker.

DevSecOps & automation
Context
Academic and personal DevSecOps project
My role
Pipeline design, implementation and build migration
Status
Implemented pipeline; historical Kaniko build approach
Deliverable
GitLab pipeline with lint, scan, build and deployment stages

Decision & evidence

Reduce the privileges required to build

Privileged Docker-in-Docker coupled the build process to an elevated Docker daemon. I migrated the project to Kaniko to remove that daemon requirement while retaining automated builds.

The architectural tradeoff was build compatibility versus privileged execution. A new implementation should reassess the maintenance status of its build tooling.

01

Overview

Designed and implemented a GitLab CI/CD pipeline with automated linting, vulnerability scanning, container build and deployment stages.

02

Objective

Integrate security into software delivery while addressing the elevated privileges associated with Docker-in-Docker builds.

03

My contribution

  • Implemented automated linting, vulnerability scanning, container build and deployment stages.
  • Identified the security risk of privileged Docker-in-Docker.
  • Migrated the build process to Kaniko, removing the Docker daemon requirement while preserving reliable automated builds.
04

Technical approach

  • Organized delivery into explicit stages so that validation and security checks form part of the build and release workflow.
  • Changed the container-build architecture from privileged Docker-in-Docker to a daemonless Kaniko approach.
05

Scope & considerations

The central architectural decision balanced build reliability with reducing privileged execution. Kaniko describes the technology used in this project, rather than a claim that it is the current preferred tool for every new pipeline.

06

Outcome

Improved secure build / release practices and pipeline consistency. Demonstrates DevSecOps, container security, automation and practical architectural decision-making.

07

Technologies

  • Docker
  • GitLab CI/CD
  • Kaniko
  • DevSecOps
  • Vulnerability Scanning
  • Automation
Next case studyEnterprise ITSM & ServiceNow Workflow DesignView all eight projects