TGViewer
DevOps & SRE notes DevOps & SRE notes @devops_sre_notes · 13.3K subscribers
Post #2318 7K
The essay walks through a hands-on pipeline that signs Kubernetes container images with Cosign, enforces them with Kyverno, and stores keys in HashiCorp Vault—all wired together in GitLab CI. You’ll leave with a reproducible template for securing your software supply chain.
https://angapov.medium.com/kubernetes-container-images-signing-using-cosign-kyverno-hashicorp-vault-and-gitlab-ci-c4e2041d1310
Medium Kubernetes container images signing using Cosign, Kyverno, HashiCorp Vault and GitLab CI Container images are the crucial part of the applications running in Kubernetes. But how can we make sure that the container images that we…
  • 👍 4
  • ❤ 2
More from @devops_sre_notes
  1. Oct 2, 2026Post #2754
  2. Oct 1, 2026Post #2753
  3. Sep 29, 2026Post #2752
  4. Sep 28, 2026Post #2751
  5. Sep 25, 2026Post #2750
  6. Sep 24, 2026Post #2749
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →