Marcio Cunha

Building Secure Continuous Delivery Pipelines with Cryptographic Artifact Signing via Cosign

Learn how to secure your software supply chain by implementing cryptographic artifact signing in continuous delivery pipelines using Cosign.

Marcio Cunha•3 min
Also available in:EspañolPortuguês
Summary
  • Modern software security requires verifying the integrity and origin of every package before execution in production environments.
  • Cosign simplifies cryptographic signing of container images and files without the traditional complexity of GPG key management.
  • Integrating automated verification into pipelines prevents malicious or tampered code from reaching production servers.
  • Cloud-based identities and OIDC providers enable secure authentication without long-lived secrets for issuers.
  • End-to-end traceability ensures rigorous compliance and total transparency across the entire development logistics chain.

The integrity challenge in the software supply chain

In contemporary software development, the speed at which new features reach production environments is remarkable. However, this agility often opens doors for new attack vectors. In practice, this means attackers can compromise external dependencies, inject malicious code into repositories, or tamper with binary packages during the compilation process. Ensuring that the artifact generated by a continuous integration pipeline is identical to what runs in production has become a critical necessity for any organization.

The software supply chain encompasses all steps, tools, and people involved from the first line of code to final user delivery. When one link in this chain fails, the entire application becomes vulnerable to silent tampering attacks. To mitigate this risk, modern engineering relies on cryptography to stamp and seal each artifact, proving mathematically and undeniably who built it and when.

The role of Cosign in artifact signing and verification

Cosign is a modern tool designed to facilitate the signing and verification of container images and other software artifacts, part of the OpenSSF ecosystem. Traditionally, signing files required dealing with complex GPG keys, painful manual rotations, and heavy operational bureaucracy. In practice, Cosign eliminates this friction by enabling keyless signatures based on managed identities and short-lived certificates issued by trusted identity providers.

When a developer or an automated pipeline signs a file with Cosign, the tool generates an elliptic curve cryptographic signature. This signature is then stored in an OCI-compliant registry, such as Docker Hub or GitHub Packages, alongside the artifact itself. Anyone or any system downloading the package in the future can instantly verify this signature, ensuring the content was not modified by malicious third parties along the way.

Integrating cryptographic signing into the continuous delivery pipeline

Automating security within a continuous integration and delivery workflow requires signing to occur right after the successful build of the artifact. In GitHub Actions, for example, we can configure a workflow that builds the container image, runs automated tests, and then triggers Cosign using the repository's own identity to securely sign the generated image.

Below is a YAML configuration snippet illustrating how this automated signing step can be structured in a modern CI/CD pipeline, utilizing OIDC tokens for authentication without static secrets.

name: Build and Sign Container
on:
  push:
    branches: [ main ]
jobs:
  build-and-sign:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      id-token: write
    steps:
      - name: Checkout repository
        uses: actions/checkout@v4
      - name: Build and push container
        run: |
          docker build -t ghcr.io/org/app:latest .
          docker push ghcr.io/org/app:latest
      - name: Install Cosign
        uses: sigstore/[email protected]
      - name: Sign container image
        run: |
          cosign sign --yes ghcr.io/org/app:latest

With this simple configuration, every version generated on the main branch receives an unnegotiable cryptographic seal. Any attempt to bypass the process and push an unsigned image will be immediately blocked in subsequent steps of the engineering workflow.

Ensuring security at deployment time

Signing artifacts is only half the process; the other half, equally crucial, is strict verification before execution. In Kubernetes-based deployment environments or isolated servers, admission controllers must reject any workload lacking a valid signature issued by the organization's authorized key or identity.

In practice, this means that even if an attacker gains access to your container registry and replaces a legitimate image with a malicious one, production servers will refuse to run it. The barrier to entry for supply chain attacks jumps exponentially, as the attacker would need to steal the exact credentials and federated identity of the build pipeline.

Final thoughts on operational security maturity

Adopting tools like Cosign transforms security from a reactive and bureaucratic layer into a native and automated component of software architecture. Although there is an initial learning curve to configure OIDC-based identities and admission policies, the operational gains and the peace of mind of knowing only verified code runs in production far outweigh the effort. Modern reliability engineering demands visibility and mathematical assurance over what we put live every day.