Hands-on Lab·Certified Kubernetes Security Specialist
Signing and Verifying Artifacts with Cosign
A digest proves bytes did not change. A signature proves who produced them, and that is the question a checksum served from the same host can never answer. This guide installs cosign, signs an artefact, verifies it, breaks it, and is precise about where the chain still has a gap.
Supply Chain Security Guide 29 of 40 Advanced
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 18 min
- Reviewed25 August 2026
Written against the versions above. cosign v2.4.3, pinned deliberately: v3 requires a bundle and a signing config and defaults to publishing to the public transparency log, which is not what you want for a private artefact or for a lab.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA6001 | 192.168.0.46 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE01 | 192.168.0.47 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE02 | 192.168.0.48 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
-
Install the tool, and verify it first
-
A keypair, and an artefact
-
Sign it, and verify the signature
-
Change one character
-
The gap this leaves