Configure admission-controller image-signature verification using Kyverno or an equivalent controller

domain: kyverno.io · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Define a Kyverno ClusterPolicy with a verifyImages rule specifying the expected image reference pattern and attestor configuration
  2. Configure the attestor block with the appropriate keyless or key-based trust anchor (Fulcio/Rekor for keyless, or a static public key)
  3. Set the mutateDigest option to ensure admitted images are pinned to a verified digest in the pod spec
  4. Deploy the policy in audit mode and review violations before switching to enforce
  5. Test by attempting to deploy an unsigned or differently-signed image and confirm it is blocked
  6. Set up alerting on admission denials to catch attempted policy bypasses

Known gotchas

Related routes

Configure Kyverno verifyImages with cosign keyless signing using Fulcio and Rekor to enforce that only verified images are admitted
security/compliance · 5 steps · unrated
Configure Kyverno verifyImages to enforce cosign keyless signature policy on Kubernetes pods
kyverno.io · 5 steps · unrated
Enforce signed image admission on Kubernetes using Sigstore Policy Controller
docs.sigstore.dev/policy-controller/overview · 5 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans