Verifying Signatures

Verifying Signatures Before Deployment

A signature protects nothing until something refuses unsigned images. cosign 6,335 verify checks that a valid signature by the given key exists for the digest; with keys and no transparency log, it must be told to skip the log check explicitly:

Verifying the signed image, and an image that was never signedShell
cosign verify --key cosign.pub --insecure-ignore-tlog=true "$IMG@$DIGEST" >/dev/null 2>v.log
echo "signed: exit $?"; grep '^  - ' v.log
docker tag l3-booknest-web:latest $IMG:web && docker push -q $IMG:web >/dev/null
cosign verify --key cosign.pub --insecure-ignore-tlog=true $IMG:web >/dev/null 2>v.log
echo "unsigned: exit $?"; grep -m1 '^Error' v.log
Output
signed: exit 0
  - The cosign claims were validated
  - Existence of the claims in the transparency log was verified offline
  - The signatures were verified against the specified public key
unsigned: exit 10
Error: no signatures found

The signed digest passed and the unsigned Nginx 75 image failed, so a deploy script can gate on the exit code. In Kubernetes 5,150 (Kubernetes), an admission controller such as Sigstore 69,885 's policy-controller or Kyverno 223,283 's verifyImages rule rejects pods whose images lack a valid signature. For keyless signatures, verification names the expected identity instead of a key, for example --certificate-identity-regexp 'https://github.com/binarybehemoth/booknest/.*' --certificate-oidc-issuer https://token.actions.githubusercontent.com 743 , which proves the image came from that repository's workflow.