Securing your Kubernetes supply chain with container image signing - Rene Schach
About this talk
This talk explores the critical topic of securing the Kubernetes supply chain through image signing, aimed at protecting containerized applications from tampering and intellectual property theft. The speaker, Rene Schach, demonstrates the use of the popular tool "cosign" for signing images and discusses its integration into CI/CD pipelines to automate the process. Additionally, he provides insights on using cosign with major public cloud infrastructures such as AWS, GCP, and Azure, and explains how to incorporate the verification of signed images within Kubernetes environments using Kyverno. This session is designed for anyone looking to enhance their image and Kubernetes deployment security, featuring short demos to showcase the complete setup in action.
More from this event
See all 108 talks →
Why are we still talking about containers? - Kelsey Hightower at ContainerDays 2025
46:56
Saxo Service Blueprint: Bridging Old and New World with Kubernetes Operators - Jinhong Brejnholt
36:25
Engineering Velocity, Building Trust: DevOps in 2025 - Stephan Stapel
33:17
Getting Started with eBPF Made Easy - Qasim Sarfraz & Michael Friese
33:05