Skip to content

Best Practices

Secure Signing Best Practices

Container image signing is a critical component of securing your supply chain. Implementing robust signing practices ensures integrity, authenticity, and traceability of your artifacts. Below are key best practices to strengthen your signing strategy with Cosign.


๐Ÿ” Key Management & Rotation

Always store signing keys in secure, isolated environments. Use hardware security modules (HSMs) or cloud KMS services (e.g., AWS KMS, Azure Key Vault, GCP Cloud KMS) to protect private keys. Avoid hardcoding keys in source code or CI/CD pipelines.

Rotate keys periodically and implement a key rotation strategy. For example:

# Rotate signing key using Cosign (example workflow)
cosign rotate-key --key new-signing-key.pem --image myregistry/myimage:latest
Ensure rotation triggers automated re-signing of existing images and updates trust anchors in your verification policies.


๐Ÿš€ CI/CD Integration

Automate signing as part of your CI/CD pipeline to ensure every build is signed. Integrate Cosign into your build process:

# GitHub Actions example: Sign image on push
- name: Sign image
  run: |
    cosign sign --key ./signing-key.pem myregistry/myimage:latest
    cosign attest --type devsecops --predicate ./predicate.json myregistry/myimage:latest
Restrict signing permissions to trusted CI/CD systems and use environment variables to manage secrets securely.


๐Ÿงช Verification Enforcement

Enforce signature verification at runtime and during deployment. Use Cosignโ€™s verify command to validate signatures before pulling images:

cosign verify --allow-insecure-registry myregistry/myimage:latest
Integrate verification into Kubernetes deployments:
# Kubernetes PodSpec with signature verification
imagePullPolicy: Always
imagePullSecrets:
  - name: my-registry-secret
Require verification as a pre-requisite for deployment using tools like Notary or Sigstore.


๐Ÿ“Š Monitoring & Auditing

Track signing and verification events using cloud-native logging tools (e.g., AWS CloudTrail, Azure Monitor, GCP Cloud Audit Logs). Set up alerts for:
- Failed verification attempts
- Key rotation events
- Unauthorized signing attempts

Audit signing keys and policies quarterly. Use Cosignโ€™s attest command to add metadata for traceability:

cosign attest --type devsecops --predicate ./predicate.json myregistry/myimage:latest


๐Ÿ”„ Regular Updates & Compliance

Keep Cosign and dependencies updated to patch vulnerabilities. Validate compliance with standards like NIST SP 800-190 or CIS benchmarks.


Key takeaways

  • Secure key management is non-negotiable; use HSMs and rotate keys regularly.
  • Automate signing in CI/CD to ensure no unsigned artifacts escape.
  • Enforce verification at runtime and during deployment to prevent tampered images.
  • Monitor and audit signing activities to detect anomalies and ensure compliance.
  • Stay updated with Cosign and security standards to mitigate emerging risks.