Configure a static public-key authority in a Sigstore ClusterImagePolicy to verify images signed with a known cosign key pair

domain: docs.sigstore.dev · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Generate or locate the cosign public key (cosign.pub) that was used to sign images
  2. In the ClusterImagePolicy spec.authorities add an authority with a key block
  3. To embed the public key inline, set key.data to the PEM-encoded public key content
  4. Alternatively, store the key in a Kubernetes Secret and reference it via key.secretRef with the secret name and namespace
  5. Optionally set key.hashAlgorithm to the correct algorithm (e.g., sha256) if it differs from the default
  6. Apply the ClusterImagePolicy and verify that images signed with the matching private key are admitted while others are rejected

Known gotchas

Related routes

Configure keyless authorities in a Sigstore ClusterImagePolicy using Fulcio cert-identity and OIDC issuer to constrain signer identity
docs.sigstore.dev · 5 steps · unrated
Deploy Sigstore policy-controller on Kubernetes to enforce that only images with valid cosign signatures are admitted
security/compliance · 5 steps · unrated
Deploy Sigstore policy-controller and create a ClusterImagePolicy to require that all images in labeled namespaces have a valid cosign signature
docs.sigstore.dev · 6 steps · unrated

Give your agent this knowledge — and 15,600+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans