Skip to content

Kyverno Signature Verification

Kyverno for Signature Verification

Kyverno is a Kubernetes policy controller that enforces security and compliance rules across clusters. When integrated with Cosign, it ensures container images are signed before deployment, enforcing strict signature verification policies. This section demonstrates how Kyverno validates image signatures, prevents unsigned or invalid images from running, and aligns with enterprise security requirements.


How Kyverno Enforces Signature Verification

Kyverno leverages Cosign’s signature validation capabilities to inspect container images during deployment. Key enforcement points include:
1. Pre-deployment validation: Kyverno checks if an image is signed using Cosign before allowing a pod to run.
2. Policy-driven rules: Custom policies define criteria for valid signatures (e.g., trusted keys, signature expiration).
3. Automated remediation: Kyverno can reject deployments or trigger alerts for non-compliant images.

This integration ensures that only images signed by trusted entities are deployed, reducing the risk of supply chain attacks.


Setting Up Kyverno with Cosign

1. Install Kyverno

Use Helm to deploy Kyverno in your Kubernetes cluster:

helm repo add kyverno https://kyverno.github.io/kyverno
helm install kyverno kyverno/kyverno --namespace kyverno

2. Configure Cosign Integration

Ensure your cluster has access to Cosign’s public keys and signing tools. Kyverno uses the cosign CLI to validate signatures.

3. Define Signature Verification Policies

Create a Kyverno policy to enforce image signing. Example:

apiVersion: kyverno.io/v1
kind: Policy
metadata:
  name: enforce-image-signature
spec:
  rules:
  - name: check-image-signature
    match:
      any:
        resources:
        - kind: Pod
    validate:
      message: "Image must be signed with a trusted key."
      pattern:
        spec:
          containers:
          - image: "*"
            imagePullPolicy: "IfNotPresent"
    annotations:
      enforce-signature: "true"
      signature-issuer: "cosign.sigstore.dev"

This policy ensures all container images are signed and validated by Cosign.


Example: Validating a Signed Image

  1. Sign an image with Cosign:

    cosign sign --key ./key.pem gcr.io/my-registry/my-image:latest
    

  2. Deploy a pod with the signed image:

    apiVersion: v1
    kind: Pod
    metadata:
      name: signed-pod
    spec:
      containers:
      - name: app
        image: gcr.io/my-registry/my-image:latest
    

  3. Observe Kyverno enforcement:
    If the image is unsigned or invalid, Kyverno blocks the deployment and logs an error.


Diagram: Kyverno + Cosign Workflow

[Developer] → [Push Image] → [Cosign Sign] → [Push to Registry]  
                                      ↓  
[Deployment] → [Kyverno Policy Check] → [Validate Signature] → [Allow/Reject Pod]

Verifying Policies and Troubleshooting

  • Check policy status:

    kubectl get policies -n kyverno
    

  • Debug failed validations:
    Use kubectl describe pod <pod-name> to see Kyverno’s rejection reason.

  • Test unsigned images:
    Deploy an unsigned image to confirm Kyverno blocks it.


Key takeaways

  • Kyverno enforces signature verification by integrating with Cosign, ensuring only trusted images run.
  • Policies define rules for valid signatures, including trusted keys and expiration checks.
  • Automation reduces manual intervention, aligning with FinOps and security best practices.
  • Combining Kyverno with Cosign strengthens multi-cloud security postures by mitigating supply chain risks.