Enforce signed image admission on Kubernetes using Sigstore Policy Controller

domain: docs.sigstore.dev/policy-controller/overview · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Install Sigstore Policy Controller via its Helm chart: `helm install policy-controller sigstore/policy-controller -n cosign-system --create-namespace`
  2. Label the target namespace with `policy.sigstore.dev/include: 'true'` to opt it in to admission enforcement
  3. Create a `ClusterImagePolicy` resource that specifies the `images` glob pattern and an `authorities` block with `keyless.url: https://fulcio.sigstore.dev` and an `identities` list constraining the OIDC issuer and subject regexp
  4. Attempt to deploy an unsigned test image and confirm the admission webhook rejects it with a policy violation message
  5. Review Policy Controller logs for `DENIED` events and integrate alerts into your security monitoring pipeline

Known gotchas

Related routes

Deploy Sigstore policy-controller on Kubernetes to enforce that only images with valid cosign signatures are admitted
security/compliance · 5 steps · unrated
Implement a signed container image promotion gate that only promotes verified images between registries
docs.sigstore.dev · 6 steps · unrated
Sign container images with a cloud KMS-backed key (not keyless Fulcio signing) using cosign and verify against that key in a deploy pipeline
docs.sigstore.dev · 5 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans