Securing your Kubernetes supply chain with container image signing - Rene Schach

37:36 · 09 Sep 2025 – 11 Sep 2025 · YouTube

About this talk

This talk explores the critical topic of securing the Kubernetes supply chain through image signing, aimed at protecting containerized applications from tampering and intellectual property theft. The speaker, Rene Schach, demonstrates the use of the popular tool "cosign" for signing images and discusses its integration into CI/CD pipelines to automate the process. Additionally, he provides insights on using cosign with major public cloud infrastructures such as AWS, GCP, and Azure, and explains how to incorporate the verification of signed images within Kubernetes environments using Kyverno. This session is designed for anyone looking to enhance their image and Kubernetes deployment security, featuring short demos to showcase the complete setup in action.

From event

ContainerDays 2025

09 Sep 2025 – 11 Sep 2025

All event videos
Back to Watch