Marcio Cunha

Kubernetes Supply Chain Security with Artifact Cryptographic Signing and Runtime Verification

Learn how to harden your Kubernetes clusters against malicious code using container digital signing with Cosign and strict runtime validation via admission policies.

Marcio Cunha•4 min
Also available in:EspañolPortuguês
Summary
  • Cryptographic signing of container images solves the silent vulnerability of binary replacement in public registries.
  • Tools like Cosign simplify the generation and storage of asymmetric keys tied to developer digital identities.
  • Admission controllers validate artifact certificates before the Kubernetes scheduler even allocates compute resources.
  • Runtime verification prevents corrupted or tampered images from executing code in the cluster even after passing the integration pipeline.
  • Continuous metadata auditing ensures complete visibility over who generated each version of software in production.

The invisible challenge of continuous delivery in modern environments

When we write code and trigger a continuous integration pipeline—the automated process that builds and tests software—we tend to blindly trust the package that arrives in our production environment. However, the current software ecosystem relies on thousands of third-party pieces, shared libraries, and base images that travel across public networks before landing on company servers. In practice, this means any vulnerable point along that journey opens the door to attacks known as dependency poisoning or silent binary tampering.

In Kubernetes environments, where hundreds of microservices spin up and down automatically, an attacker who manages to inject malicious code into a container image gains privileged access to the entire infrastructure. Securing this journey requires abandoning the belief that the central image registry is an inviolable vault. We must cryptographically ensure that the file executed today on the server is precisely the one that left the developer's machine, without any alteration along the way.

The anatomy of cryptographic container signing

To solve this trust dilemma, modern engineering has adopted asymmetric cryptography, a method based on mathematical key pairs: a private key kept strictly secure and a public key that anyone can use to check authenticity. When a developer or automated system finishes building a container image, they use the private key to digitally sign the package, generating an unalterable cryptographic seal.

In practice, this process attaches signature metadata directly to the image registry, associating the artifact with a verifiable identity. If an attacker alters a single byte inside the container image, the mathematical signature immediately stops matching, triggering a violation alert. Tools like Cosign, a project maintained by the CNCF foundation, popularized this approach by allowing signatures without the complexity of managing traditional X.509 certificates, integrating natively with cloud-based identities.

Implementing digital signing in automated pipelines

Integrating artifact signing into daily workflows does not require drastic changes to engineer routines, provided the delivery pipeline is well structured. The ideal time to perform this operation is right after successful security testing and the upload of the final image to the central registry. Below, we exemplify how the signing command can be executed in an automated step using a securely stored private key.

cosign sign --key k8s-release-key.pem minha-empresa.azurecr.io/app/payments-service:v1.2.4

In this step, the command reads the private key and generates an encrypted token published in the same registry where the image is hosted. It is crucial to ensure the private key is never exposed in public logs or stored unencrypted in the source code repository. Mature enterprise environments typically rely on password vaults or cloud key management services to safeguard this critical secret.

Ensuring integrity with runtime verification

Signing the image before sending it to production is only half the battle; true security happens when the Kubernetes cluster refuses to run any code lacking a valid authenticity seal. To achieve this level of control, we use validators known as admission controllers, which intercept every pod creation request and check if the artifact has a legitimate signature attached.

Tools like Kyverno or Policy Controller act as strict guardians at the cluster's entrance door. They evaluate predefined policies determining that if an image was not signed by the authorized corporate key, Kubernetes simply blocks its execution and reports the incident. In practice, this means even if someone bypasses access control and tries to launch a malicious container directly, the platform will automatically reject the command.

Orchestrating security policies and operational exceptions

Configuring absolute blocking policies across a large fleet of servers requires planning to avoid undue disruptions in legacy systems or staging environments. The ideal approach is to start adopting admission controllers in audit mode, where the cluster merely logs warnings about unsigned images without interrupting application uptime. This allows the team to map all external dependencies lacking cryptographic traceability.

As the signing process is embraced by development teams, policies are progressively tightened until full blocking is achieved in production environments. Furthermore, it is important to establish controlled exceptions for official images from third-party vendors, which can be verified using public keys provided by the manufacturers themselves, keeping the supply chain rigorously audited end-to-end.

Final considerations on cloud operational resilience

Supply chain security in Kubernetes is no longer a technical differentiator but a fundamental requirement for any organization dealing with sensitive data and critical infrastructures. The combination of cryptographic artifact signing and strict runtime verification creates an insurmountable barrier against code tampering and malicious dependency injection. By adopting these practices, engineering teams regain full control over what runs on their servers, ensuring a resilient, auditable enterprise environment prepared for future security challenges.