Shah, Pratham Deepak (2025) A DevSecOps Framework for Automated Container Security in CI/CD Pipelines. Masters thesis, Dublin, National College of Ireland.
Preview |
PDF (Master of Science)
Download (453kB) | Preview |
Preview |
PDF (Configuration Manual)
Download (300kB) | Preview |
Abstract
Containerization and cloud-native delivery pipes have expedited the delivery of software at the cost of augmented misconfigurations that in most cases are not detected by the conventional CI/CD processes. The currently available DevSecOps tools are mostly used without other tools, and they are not empirically validated when implemented as an automated security layer built into a pipeline. The present work schedules and develops a multi-layered multi-monitoring configuration misconfiguration apparatus that encumbers fixed checking, Docker file harmony and Kubernetes-design verification and policy-ascode structure into the CI/CD procedure. Dockerfile and Kubernetes manifests were analyzed with Trivy, Dockle and Kube-linter using a controlled comparative design under the intention of being misconfigured. The automated pipeline was able to identify a great number of medium and low severity vulnerabilities in package dependencies, two Docker image hygiene exposures, and four substantive Kubernetes manifest exposures, such as mutable image labels and writable root filesystems and missing CPU and memory requests. None of these findings were detected using a baseline pipeline that was not automated. Even though no OPA Gatekeeper enforcement or complete execution of GitHub actions were done, the misconfigurations observed can be directly related to violations that are typically blocked in policy-protected settings. The findings show that shift-left, automated detection of misconfigurations delivers a much better visibility and avoids risky configurations spread to the deployment phases with only a moderate operational burden. The research adds empirically tested and reproducible framework of DevSecOps which tackles reported gaps in studies of security automation in CI/CD research and helps organizations adapt cloud-native security position.
| Item Type: | Thesis (Masters) |
|---|---|
| Supervisors: | Name Email Jayasekera, Evgeniia UNSPECIFIED |
| Subjects: | Q Science > QA Mathematics > Electronic computers. Computer science T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science T Technology > T Technology (General) > Information Technology > Cloud computing Q Science > QA Mathematics > Computer software > Computer Security T Technology > T Technology (General) > Information Technology > Computer software > Computer Security |
| Divisions: | School of Computing > Master of Science in Cyber Security |
| Depositing User: | Ciara O'Brien |
| Date Deposited: | 04 Sep 2026 10:19 |
| Last Modified: | 04 Sep 2026 10:19 |
| URI: | https://norma.ncirl.ie/id/eprint/9828 |
Actions (login required)
![]() |
View Item |
Tools
Tools