問題文
A team wants security checks to influence what runs in the cluster without adding a human step. Which approach is consistent with both the DevSecOps description and the GitOps principles?
選択肢
- Express the constraints as declarations that are evaluated automatically, so that a change violating them is rejected without anyone having to intervene.
- Configure the agent to suspend reconciliation whenever a scan reports a finding, so that nothing further is applied until the finding has been resolved and the runtime is therefore never moved into a state that violates a constraint.
- Have the build system refuse to publish an artifact that fails a scan, which removes the need for any constraint to be evaluated after that point.
- Give the security team write access to the runtime so they can remove anything that violates a constraint.