Q: Your security office mandates SLSA Level 3 compliance across all 400 engineering microservices. How do you integrate automated SBOM generation and keyless image signing into centralized platform CI workflows without breaking developer release velocity?
Baking cryptographic container image signing and Software Bill of Materials (SBOM) generation into centralized Golden Path CI workflows.
Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Automate SBOM Generation Using Syft in Golden Path Workflow
Immediately after Docker container build, execute Anchore Syft to generate a CycloneDX / SPDX JSON bill of materials and attach it to the OCI image registry.
- name: Generate SBOM
uses: anchore/sbom-action@v0
with:
image: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }}
format: spdx-json
output-file: sbom.spdx.json
Execute Keyless Cosign Signing via GitHub Actions OIDC
Use Sigstore Cosign with GitHub's OIDC token (`id-token: write`). Cosign signs the image using short-lived Fulcio certificates, publishing signatures and SBOMs to the container registry without managing long-lived private keys.
- name: Sign Container Image
run: |
cosign sign --yes \
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }}
cosign attach sbom --sbom sbom.spdx.json \
${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }}
Enforce Admission Verification via Kyverno / Policy Controller
Deploy a Kyverno ClusterPolicy in Kubernetes blocking any container image that lacks a valid Cosign signature issued by the organization's GitHub repository identity.
- Generate automated SPDX/CycloneDX SBOMs during container build stages using Syft.
- Sign container images keylessly using Sigstore Cosign and GitHub OIDC tokens.
- Enforce signature verification in Kubernetes clusters via Kyverno admission webhooks.