Someone pushes a malicious image to your registry. Without image signing, Kubernetes pulls and runs it. Cosign adds cryptographic signatures to container images so you can verify who built them and that they have not been tampered with.
Keyless Signing
Cosign's keyless mode uses your identity provider (GitHub, Google, Microsoft) instead of managing private keys:
# Install
brew install cosign
# Sign (opens browser for OIDC auth)
cosign sign myorg/order-api:v1.0
# Verify
cosign verify myorg/order-api:v1.0 \
--certificate-identity=build@myorg.com \
--certificate-oidc-issuer=https://accounts.google.comNo private keys to manage, rotate, or protect. The signature is tied to your identity.
CI/CD Signing
GitHub Actions
jobs:
build-and-sign:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write # Required for keyless signing
packages: write
steps:
- uses: actions/checkout@v4
- name: Build and push
run: |
docker build -t ghcr.io/myorg/order-api:${{ github.sha }} .
docker push ghcr.io/myorg/order-api:${{ github.sha }}
- name: Install Cosign
uses: sigstore/cosign-installer@main
- name: Sign image
run: |
cosign sign --yes \
ghcr.io/myorg/order-api:${{ github.sha }}
env:
COSIGN_EXPERIMENTAL: 1GitHub's OIDC token proves the image was built by this specific workflow in this specific repository.
Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Verify Signatures
# Verify with identity constraints
cosign verify ghcr.io/myorg/order-api:v1.0 \
--certificate-identity-regexp=".*@myorg.com" \
--certificate-oidc-issuer=https://token.actions.githubusercontent.com
# Output
Verification for ghcr.io/myorg/order-api:v1.0 --
The following checks were performed:
- The cosign claims were validated
- The claims were present in the transparency log
- The signatures were integrated with Rekor
- The certificate identity matchedAttach Metadata
Software Bill of Materials (SBOM)
# Generate SBOM
syft ghcr.io/myorg/order-api:v1.0 -o spdx-json > sbom.json
# Attach to image
cosign attach sbom --sbom sbom.json ghcr.io/myorg/order-api:v1.0
# Sign the SBOM attestation
cosign attest --predicate sbom.json \
--type spdxjson ghcr.io/myorg/order-api:v1.0Vulnerability Scan Results
# Scan and attest
trivy image --format cosign-vuln ghcr.io/myorg/order-api:v1.0 > vuln.json
cosign attest --predicate vuln.json \
--type vuln ghcr.io/myorg/order-api:v1.0The image now carries its SBOM and vulnerability scan as signed attestations.
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Enforce in Kubernetes
Kyverno Policy
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: verify-image-signatures
spec:
validationFailureAction: Enforce
rules:
- name: verify-cosign-signature
match:
any:
- resources:
kinds: ["Pod"]
verifyImages:
- imageReferences: ["ghcr.io/myorg/*"]
attestors:
- entries:
- keyless:
subject: "*@myorg.com"
issuer: "https://token.actions.githubusercontent.com"Unsigned images are rejected. Only images signed by your GitHub Actions workflows can run.
Sigstore Policy Controller
helm install policy-controller sigstore/policy-controller \
--namespace cosign-system --create-namespaceapiVersion: policy.sigstore.dev/v1beta1
kind: ClusterImagePolicy
metadata:
name: require-signatures
spec:
images:
- glob: "ghcr.io/myorg/**"
authorities:
- keyless:
identities:
- issuer: https://token.actions.githubusercontent.com
subjectRegExp: "https://github.com/myorg/.*"Key-Based Signing
For air-gapped environments without OIDC:
# Generate key pair
cosign generate-key-pair
# Sign with private key
cosign sign --key cosign.key ghcr.io/myorg/order-api:v1.0
# Verify with public key
cosign verify --key cosign.pub ghcr.io/myorg/order-api:v1.0Store cosign.key in your CI/CD secrets. Distribute cosign.pub to clusters.
The Full Supply Chain
Developer → GitHub → Build → Sign → Push → Verify → Deploy
↓ ↓ ↓
SBOM Signature Admission
Scan Attestation ControlEvery image in production has a verified identity, a signed SBOM, and a vulnerability scan attestation. This is software supply chain security.
---
Ready to go deeper? Master container security with hands-on courses at CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Sigstore Container Image Signing
Sigstore provides keyless signing for container images and software artifacts. Learn how to sign images with Cosign, verify signatures in Kubernetes.
Falco Runtime Security Kubernetes
Falco detects runtime threats in Kubernetes using eBPF. Learn how to set up Falco for container security monitoring, write custom rules, and integrate.
Trivy Container Vulnerability Scanner
Trivy scans container images, filesystems, and IaC for vulnerabilities and misconfigurations. Learn how to integrate Trivy into your CI/CD pipeline.
Crossplane Infrastructure as Code
Crossplane lets you manage cloud infrastructure using Kubernetes custom resources. Learn how it works, how it compares to Terraform, and when to choose.
Dagger CI/CD Pipelines as Code
Dagger lets you write CI/CD pipelines in real programming languages instead of YAML. Learn how Dagger works, how it compares to GitHub Actions.
Data Sovereignty Infrastructure
Implement data sovereignty with multi-region cloud infrastructure, GDPR compliance patterns, and geopatriation strategies for regulated workloads.
Explore topics
Browse more articles on the topics covered here.