kodebeat / papers / security

Enforcing image signatures without owning the cluster

An init container that blocks unsigned images at pod start.

Verifies image signatures with cosign before the main workload starts, so a signature that does not verify means the pod never runs. Key-based or keyless, configured entirely through environment variables, and adoptable one workload at a time with no webhook and no platform-team ticket. The repository is candid about what this buys: an init container is a speed bump, not a boundary.

What is in it

  • The problem — what goes unanswered without it, and who notices first.
  • Why the obvious alternative falls short — stated plainly, including where it is the better choice.
  • How it works — the method, not a feature list.
  • Concrete use cases — with console output quoted from the repository, never reconstructed.
  • The methodology behind any number it emits — every term shown, so the figure survives a question.
  • What it deliberately does not do — the section most papers leave out.

Part of the Security & supply chain theme.

Get the PDF

One email with the download link, and this paper already selected. No follow-up sequence.

Send it to me