Marcio Cunha

Continuous Container Image Auditing with Cosign and Admission Controller

Learn how to secure your cloud environment using cryptographic signatures with Cosign and strict runtime validation via Kubernetes Admission Controllers.

Marcio Cunha•4 min
Also available in:EspañolPortuguês
Summary
  • Package integrity in production environments requires cryptographic guarantees that go beyond traditional hash checks.
  • Cosign enables digital image signing directly within CI pipelines without the complexity of managing exposed private keys.
  • Validating artifacts in the Admission Controller physically prevents unauthorized workloads from running on cluster nodes.
  • Public-key-based policies ensure that only artifacts originating from audited pipelines reach the production environment.
  • Continuous artifact observability drastically reduces the attack surface against software supply chain vulnerabilities.

The invisible challenge of the software supply chain

In modern software development, we constantly rely on third-party libraries, open-source packages, and pre-built container images. In practice, this means much of the software running in production was crafted by unknown teams in remote locations. When an attacker manages to inject malicious code into a common dependency, the entire downstream ecosystem silently inherits that flaw. Protecting production environments requires going beyond version checking to reach the cryptographic level.

Ensuring that the artifact executed on the server is identical to the one that passed security testing is the core goal of image signing. Without this trust mechanism, any malicious actor with access to the central image registry can swap a legitimate package for a tampered version. Continuous auditing turns blind trust into rigorous mathematical verification with every new delivery cycle.

Understanding cryptographic signatures with Cosign

Cosign is a tool specifically designed to simplify the signing, verification, and storage of container artifacts using modern cryptography. In practice, it acts like a digital notary that seals the software package and attests to its authentic origin. Using asymmetric keys, where a private key seals the file and a public key validates the signature, the system makes forgery impossible without compromising the secret key.

Unlike legacy methods that required complex management of traditional X.509 certificates, Cosign integrates seamlessly with cloud-based identities and modern authentication providers. This means the developer's or pipeline's own identity can serve as proof of authenticity, eliminating static key files forgotten on vulnerable servers. The result is a transparent process that fits naturally into existing automation workflows.

Runtime validation architecture in Kubernetes

Signing images during software builds solves half the problem, but the system must ensure that the signed artifact is truly the only one allowed to run. This is where the Admission Controller comes in, a Kubernetes component that intercepts cluster requests before objects are persisted or executed. In practice, it acts like a strict security guard at the party door, demanding a signed invitation before letting any container enter.

When a deployment command is triggered in the cluster, the Admission Controller couples an automated check to validate the cryptographic signature of the image against a trusted public key. If the signature is missing, corrupted, or belongs to an unauthorized key, execution is summarily rejected. This barrier prevents unaudited images from entering production, even if an attacker gains partial access credentials to the cluster.

Implementing automated verification with security policies

To put this architecture into practice, we configure policies that govern cluster behavior for every requested image. Implementation requires defining clear rules about which issuers are trusted and which exceptions, if any, should be tolerated in test environments. In practice, the process involves the following operational steps in your pipeline and infrastructure:

  1. Generate a cryptographic key pair using the Cosign command-line tool in your secure build environment.
    cosign generate-key-pair
  2. Sign the newly built image in your container registry using the previously generated private key.
    cosign sign --key cosign.key my-registry.io/app/service:v1.0.0
  3. Install and configure an admission validator, such as Kyverno or Policy Controller, on your Kubernetes cluster.
    kubectl apply -f https://github.com/kyverno/kyverno/releases/latest/download/install.yaml
  4. Apply the verification policy requiring a valid signature based on your public key.
    apiVersion: kyverno.io/v1
    kind: ClusterPolicy
    metadata:
      name: verify-image-signature
    spec:
      validationFailureAction: Enforce
      rules:
        - name: verify-cosign
          match:
            any:
              - resources:
                  kinds:
                    - Pod
          verifyImages:
            - imageReferences:
                - "my-registry.io/app/*"
                  attestations:
                    - predicateType: custom
                      fullyQualified: true
  5. Monitor cluster audit logs to identify attempts to execute unsigned images.
    kubectl logs -n kyverno -l app=kyverno --tail=100

Operational considerations and performance impacts

Adding cryptographic checks and runtime interceptions introduces minor overhead that must be managed carefully. In practice, querying remote image registries to check signatures can add precious milliseconds to pod startup times. To mitigate this impact, validation tools typically cache verification results and use efficient communication strategies with the container registry.

Another critical point is cryptographic key lifecycle management. If a private key leaks, the team must revoke it immediately and reissue new signatures for the entire production image catalog. Establishing automated key rotation and periodic auditing routines ensures supply chain security remains robust without halting engineering delivery pace.

Final Considerations

Container infrastructure security is no longer an aesthetic differentiator; it is a fundamental requirement for digital survival. Combining cryptographic signatures via Cosign with active blocking in Admission Controllers turns the development pipeline into a high-reliability environment. In practice, this approach shields the business against silent tampering and ensures only rigorously audited code reaches end-user eyes.

Implementing these practices requires cultural and technical planning, but the return on investment in operational peace of mind is immeasurable. By removing blind server trust and replacing it with mathematics and automated validation, your engineering gains the maturity needed to navigate the complex challenges of modern cloud computing.