Hardening Container Supply Chains: Cosign Signatures and SBOM Attestations
Securing code repositories is only half the battle. If unauthorized or tampered container images can be deployed to production, your infrastructure remains vulnerable to supply chain attacks.
In the AustinSS Blogs pipeline, every container image built on Azure DevOps is cryptographically signed using Sigstore Cosign and paired with a machine-readable Software Bill of Materials (SBOM) before deployment.
1. Keyless Container Signing with Cosign & OIDC
Traditional code signing required managing private GPG keys. If the private key leaked, trust was compromised. With Sigstore keyless signing, short-lived Fulcio certificates are issued based on Azure DevOps OIDC token identity:
# Generate short-lived GCP ID token for signing
sigstore_token=$(echo "$id_token_resp" | jq -r .token)
# Cryptographically sign container image digest
cosign sign --yes \
--identity-token="$sigstore_token" \
"$REPO:$IMAGE_DIGEST"
# Verify signature against sanctioned service account identity
cosign verify \
--certificate-identity="sa-tf-website-dev@austinss-web-dev.iam.gserviceaccount.com" \
--certificate-oidc-issuer="https://accounts.google.com" \
"$REPO:$IMAGE_DIGEST"
2. Automated SBOM Generation with Syft
Every build invokes Anchore Syft to catalog all operating system packages, Python wheels, and transitive dependencies in standardized CycloneDX and SPDX JSON formats:
syft "$REPO:$IMAGE_DIGEST" -o cyclonedx-json=sbom.json
cosign attest --yes --predicate sbom.json "$REPO:$IMAGE_DIGEST"
This enables automated vulnerability scanners and compliance auditors to inspect the exact bill of materials running in production.