Interactive tutorial teaching container image security using Sigstore's Cosign tool.
- Generate signing keys with Cosign
- Sign container images cryptographically
- Verify image authenticity and integrity
- Understand supply chain security risks
Unsigned container images can be tampered with between build and deployment. Signing provides:
- Integrity - Detect modifications
- Authenticity - Verify the source
- Trust - Run only verified images
- Create an unsigned image
- Demonstrate vulnerability by injecting malicious code
- Install Cosign
- Generate cryptographic key pair
- Sign a container image
- Verify signatures and prevent tampering
- Docker
- Cosign (Sigstore)
No installation required - runs entirely in your browser at https://killercoda.com/putastep/scenario/docker-signing