Signing and Verifying Build Artifacts thumbnail

Signing and Verifying Build Artifacts

By Richard Augenti

Sign container images and provenance attestations in the pipeline, then enforce verification at deploy time so an unsigned or tampered artifact cannot run.

Browse
Skill Level: Intermediate Duration: 60 min Supply Chain SecurityDevSecOps
Sign in to start

Free to browse. Takes about 60 minutes once you start.

Lab Overview

The receipts-api deploy gate pulls whatever image reference it is handed and runs it. Nothing checks that the image is the one your pipeline actually built, so anyone who can push to the registry - or simply move a tag - can get their image deployed under your service's name.

In this lab you sign your legitimate image with cosign and turn the deploy gate into a checkpoint that rejects anything not signed by your key. This closes the "attacker pushed a malicious image" path that vulnerability scanning never sees, because a malicious image can be perfectly free of CVEs.

Everything runs against a local registry on localhost:5555. Signing is key-based and offline - no transparency log and no external services are contacted.

What to Expect

  • Environment: a single Ubuntu machine you connect to over SSH. cosign runs as a container through the ./cosign wrapper, and a local registry is already running with two images loaded. No cluster required.
  • Access: SSH credentials are generated for your session and shown in the workspace. They are destroyed when the lab ends.
  • Offline: signing and verification are entirely local and key-based, so nothing you sign leaves the machine.
  • Progress: your work is not saved. If the lab expires or you quit, the machine and everything on it is destroyed.

What are hands-on labs?

A lab is a real environment, not a simulation. You get a live machine with the tooling already installed, a task taken from production work, and root access to take it apart. Nothing is mocked, nothing is multiple choice. It either works or it doesn't.

Real tooling

The same commands you would run at work, on a machine that is already set up for them. No screenshots, no sandboxed toy version.

Break it freely

Everything is disposable. When the clock runs out the environment is destroyed with everything in it, so there is no reason to be careful.

Useful on Monday

Built by engineers who run these systems in production. Skills you can apply to your own stack the same week, not exam preparation.

Browse labs