Welcome to Securing the Software Supply Chain with Sigstore and Cosign. Software supply chain attacks, where malicious actors compromise a build pipeline to inject malware into legitimate software updates (e.g., SolarWinds), are the premier threat in modern DevOps. To combat this, organizations must cryptographically sign their artifacts and container images.

1. The Key Management Nightmare

Historically, signing artifacts required managing long-lived PGP or GPG keys. Developers lost keys, revoked them improperly, or stored them insecurely on laptops. Automating this in CI/CD pipelines meant storing highly privileged private keys in Jenkins or GitHub Actions, presenting a massive attack surface.

2. Keyless Signing with Sigstore

Sigstore is a Linux Foundation project that makes code signing transparent and "keyless". It relies on OpenID Connect (OIDC) identities. When a developer or a CI/CD bot wants to sign an image, they authenticate via OIDC (e.g., using GitHub or Google credentials). Sigstore's Certificate Authority (Fulcio) issues a short-lived X.509 certificate tied to that identity, valid for just 10 minutes.

3. Immutable Transparency Logs (Rekor)

Once the signature is generated with the short-lived key, the signature and the certificate are immediately recorded in Rekor, a tamper-resistant, append-only transparency log. Because the log is immutable, the signature remains valid and verifiable long after the 10-minute certificate has expired.

4. Using Cosign in the Pipeline

Cosign is the CLI tool used to interact with Sigstore. In a CI/CD pipeline, after a container image is built and pushed to a registry, you simply run `cosign sign <image-uri>`. During deployment, Kubernetes admission controllers (like Kyverno or OPA Gatekeeper) run `cosign verify`. If the image signature is invalid or absent from the Rekor log, the admission controller blocks the deployment.

Conclusion

By removing the burden of long-lived key management and relying on short-lived certificates backed by immutable ledgers, Sigstore and Cosign provide a pragmatic, highly secure method to ensure the provenance and integrity of the software supply chain.