Cryptographic Image Signing
Every image is signed using Sigstore's keyless signing infrastructure. Signatures are recorded in a tamper-evident transparency log, enabling verification before deployment.
- Keyless signing with Sigstore Cosign
- Transparency log entries for all signatures
- Verification in CI/CD pipelines
- Policy enforcement with admission controllers
# Verify image signature
cosign verify registry.imagesentinel.io/python:3.12 \
--certificate-identity-regexp=".*@imagesentinel.io" \
--certificate-oidc-issuer="https://accounts.google.com"
✓ Transparency log entry verified
✓ Signature verified against certificate
✓ Certificate chain verified