Chuyển đến nội dung chính
Bảo mật

Supply Chain Security: SLSA, SBOM và Sigstore cho artifact production

Sau xz, npm typosquat và build poisoning, supply chain attack đã trở thành vector phổ biến nhất. SLSA + SBOM + Sigstore là bộ ba khung tiêu chuẩn mở giúp bạn chứng minh artifact được build từ đâu, bằng gì, bởi ai.

Supply Chain Security: SLSA, SBOM và Sigstore cho artifact production
Câu hỏi audit khó nhất hiện nay không phải "code có CVE không?" mà là "làm sao chứng minh artifact đang chạy production được build từ chính source này, không bị inject?".

Ba loại supply chain attack phổ biến

  • Dependency confusion / typosquat (npm, pypi, RubyGems): publish package có tên gần giống thư viện nội bộ.
  • Source compromise (xz utils, Codecov bash uploader): inject malicious code vào dự án thượng nguồn.
  • Build poisoning (SolarWinds): compromise build server, inject vào artifact mà source code vẫn sạch.

Khung tiêu chuẩn ứng phó là SLSA (Supply-chain Levels for Software Artifacts) do OpenSSF maintain.

SLSA — bốn cấp độ build integrity

LevelYêu cầu chính
L1Build có document, sinh provenance cơ bản.
L2Build chạy trên hosted CI, provenance được sign, source theo version control.
L3Build trong môi trường isolated/hardened, provenance không thể bị giả mạo bởi user.
L4Hermetic, reproducible build, two-party review.

Mục tiêu thực tế cho phần lớn tổ chức: SLSA Build L2-L3. L4 còn hiếm và tốn kém.

SBOM: CycloneDX hay SPDX?

Hai format chuẩn:

  • CycloneDX (OWASP): tập trung security use case, hỗ trợ vulnerability, services, ML model. Tool ecosystem phong phú (Trivy, Syft, Dependency-Track).
  • SPDX (Linux Foundation): tập trung license compliance, được nhiều regulator chấp nhận (US EO 14028).

Chọn 1 chính, có thể export sang format kia khi cần. Mỗi artifact production phải có SBOM được sinh tự động trong CI và lưu cùng artifact.

Sigstore: keyless signing cho mọi artifact

Sigstore gồm 3 component:

  • Cosign: CLI sign/verify image, blob, attestation.
  • Fulcio: CA cấp short-lived cert dựa OIDC identity (5 phút TTL).
  • Rekor: transparency log bất biến lưu mọi signature — kiểm tra xem có signature nào bất thường được tạo bằng identity của bạn không.

Lợi ích lớn nhất: không có private key cần lưu, rotate hay backup.

Provenance & in-toto attestation

Provenance là metadata mô tả: ai build, từ source nào, bằng tool gì, vào lúc nào. Format chuẩn là in-toto attestation với predicate type https://slsa.dev/provenance/v1.

Workflow GitHub Actions có generator chính thức:

jobs:
  build:
    outputs:
      digest: ${{ steps.push.outputs.digest }}
    # ... build & push image

provenance: needs: [build] permissions: id-token: write packages: write contents: read uses: slsa-framework/slsa-github-generator/.github/workflows/[email protected] with: image: ghcr.io/org/app digest: ${{ needs.build.outputs.digest }} registry-username: ${{ github.actor }}

Workflow này build trong reusable workflow isolated, sinh provenance + ký bằng Cosign keyless — đạt SLSA L3 không cần code thêm.

Verify provenance trước deploy

Bằng cosign verify-attestation:

cosign verify-attestation --type slsaprovenance \
  --certificate-identity-regexp "https://github.com/org/.+/.github/workflows/build.yml@.+" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  ghcr.io/org/app@sha256:...

Hoặc enforce trong cluster qua Kyverno verifyImages với attestor là OIDC subject. Pod sẽ bị admission từ chối nếu image không có provenance đúng.

Quản lý dependency thông minh

  • Pin theo digest/lockfile: package-lock.json, poetry.lock, go.sum. Không bao giờ latest.
  • Pin GitHub Action theo SHA chứ không phải tag — tag có thể bị move.
  • Vendor mirror cho package nội bộ (Artifactory, Nexus) thay vì pull thẳng từ npm/pypi public.
  • Renovate/Dependabot có policy: auto-merge patch, manual review minor/major, có cooldown để tránh chính bản malicious vừa publish.

Checklist supply chain ngắn

  • Mọi artifact production có SBOM CycloneDX/SPDX và được lưu trữ.
  • Image được sign Cosign keyless, signature lưu Rekor.
  • Build chạy trong reusable workflow isolated (đạt SLSA L2-L3).
  • Cluster có policy verify signature + provenance trước khi admit pod.
  • Dependency pin theo lockfile + digest, mirror nội bộ.
  • Dependency-Track theo dõi long-tail CVE qua SBOM.

Kết luận

Supply chain security không còn là tuỳ chọn — EU CRA, US EO 14028 và nhiều khách hàng enterprise đã yêu cầu SBOM và signed artifact trong RFP. Tin tốt: stack mở Sigstore + SLSA + CycloneDX cho phép đạt SLSA L3 với chi phí gần như bằng 0 nhờ reusable workflow của OpenSSF. Hãy coi đây là baseline kỹ thuật cần có trong 2026.

DUY TRAN
Tác giả

DUY TRAN

Pursuing an AI-first mindset and intelligent system architecture. I build solutions by combining technology, creativity, and the ability to see structure in chaos — the foundation for becoming a Solution Architect.

Bình luận

Bài viết liên quan