DevSecOps for Air Gap & Limited-Connection Systems. https://zarf.dev/
-
Updated
Apr 23, 2023 - Go
DevSecOps for Air Gap & Limited-Connection Systems. https://zarf.dev/
An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster
This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)
Integrates Spiffe and Vault to have secretless authentication
Example goreleaser + github actions config with keyless signing and SBOM generation
Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect
Stream, Mutate and Sign Images with AWS Lambda and ECR
Proof of concept that uses cosign and GitHub's in built OIDC for actions to sign container images, providing a proof that what is in the registry came from your GitHub action.
Docker Registry Authentication Made Simple
Example code repo for blog post https://chainguard.dev/posts/2022-01-07-cosign-aws-codepipeline
Sign your artifacts, source code or container images using Sigstore tools, Save the Signatures you want to use, and Validate & Control the deployments to allow only the known Sources based on Signatures, Maintainers & other payloads automatically.
Sigstore Homebrew Tap
A demonstration of how GoReleaser can help us to make software supply chain more secure by using bunch of tools such as cosign, syft, grype, slsa-provenance
Add a description, image, and links to the cosign topic page so that developers can more easily learn about it.
To associate your repository with the cosign topic, visit your repo's landing page and select "manage topics."