department-of-veterans-affairs / va.gov-team

Public resources for building on and in support of VA.gov. Visit complete Knowledge Hub:
https://depo-platform-documentation.scrollhelp.site/index.html
284 stars 206 forks source link

Application Hosting and Deployment: Container scanning for enhanced security #36286

Open jhouse-solvd opened 2 years ago

jhouse-solvd commented 2 years ago

Problem Statement

Containerized applications and associated components can pose a risk to security. There can be vulnerabilities with software packages related to the operating system, the application, or various dependencies.

How might we

...scan containers and their components to identify potential security threats?

Hypothesis or Bet

How will this initiative impact the quality of VFS or VSP teams' work? How will this initiative be easy for VFS or VSP teams? Or how will it be easier than what they did before?

We will know we're done when... ("Definition of Done")

What requirements does this project need to meet for you to finish this initiative?

Known Blockers/Dependencies

List any blockers or dependencies for this work to be completed

Projected Launch Date

TBD

Launch Checklist

Guidance (delete before posting)

Is this service / tool / feature...

... tested?

... documented?

... measurable

When you're ready to launch...

Required Artifacts

Documentation

Testing

Measurement

TODOs

jhouse-solvd commented 2 years ago

The first epic should likely be Discovery. This would be a good place to list questions and concerns that we'd like to address, and how various solutions might address those.