Best Practices
Secure Signing Best Practices¶
Container image signing is a critical component of securing your supply chain. Implementing robust signing practices ensures integrity, authenticity, and traceability of your artifacts. Below are key best practices to strengthen your signing strategy with Cosign.
๐ Key Management & Rotation¶
Always store signing keys in secure, isolated environments. Use hardware security modules (HSMs) or cloud KMS services (e.g., AWS KMS, Azure Key Vault, GCP Cloud KMS) to protect private keys. Avoid hardcoding keys in source code or CI/CD pipelines.
Rotate keys periodically and implement a key rotation strategy. For example:
# Rotate signing key using Cosign (example workflow)
cosign rotate-key --key new-signing-key.pem --image myregistry/myimage:latest
๐ CI/CD Integration¶
Automate signing as part of your CI/CD pipeline to ensure every build is signed. Integrate Cosign into your build process:
# GitHub Actions example: Sign image on push
- name: Sign image
run: |
cosign sign --key ./signing-key.pem myregistry/myimage:latest
cosign attest --type devsecops --predicate ./predicate.json myregistry/myimage:latest
๐งช Verification Enforcement¶
Enforce signature verification at runtime and during deployment. Use Cosignโs verify command to validate signatures before pulling images:
# Kubernetes PodSpec with signature verification
imagePullPolicy: Always
imagePullSecrets:
- name: my-registry-secret
๐ Monitoring & Auditing¶
Track signing and verification events using cloud-native logging tools (e.g., AWS CloudTrail, Azure Monitor, GCP Cloud Audit Logs). Set up alerts for:
- Failed verification attempts
- Key rotation events
- Unauthorized signing attempts
Audit signing keys and policies quarterly. Use Cosignโs attest command to add metadata for traceability:
๐ Regular Updates & Compliance¶
Keep Cosign and dependencies updated to patch vulnerabilities. Validate compliance with standards like NIST SP 800-190 or CIS benchmarks.
Key takeaways¶
- Secure key management is non-negotiable; use HSMs and rotate keys regularly.
- Automate signing in CI/CD to ensure no unsigned artifacts escape.
- Enforce verification at runtime and during deployment to prevent tampered images.
- Monitor and audit signing activities to detect anomalies and ensure compliance.
- Stay updated with Cosign and security standards to mitigate emerging risks.