CascadeGuard

Event-driven container image lifecycle management and supply chain attack prevention.

Architecture

  • CLI-first — Python-based CLI for scanning, promoting, and managing container images
  • Event-driven — responds to registry events, CI triggers, and scheduled scans
  • Multi-repo — core CLI, GitHub Actions, hardened base images, exemplars
  • GitOps — state repos track desired image state, ArgoCD applies

Key Facts

Components

ComponentRepoPurpose
Core CLIcascadeguardImage lifecycle management
Actionscascadeguard-actionsReusable GitHub Actions
Open Secure Imagescascadeguard-open-secure-imagesHardened base images, daily CVE scanning
Exemplarcascadeguard-exemplarExample state repo
Docscascadeguard-docsDocumentation site

Subsumes

  • image-factory — Image Factory’s functionality is being migrated into CascadeGuard CLI
  • k8s-lab — Platform where CascadeGuard deploys
  • decisions — CascadeGuard ADRs