Repository navigation
docs: correct Docker image verification instructions for cosign 3 (backport #4555 to V6.2) - #4556
Merged
Merged
Conversation
The signing job runs cosign 3, which stores a signature as a Sigstore bundle attached through the OCI referrers API instead of the sha256-<digest>.sig tag. The verification guide still described the cosign 2 layout: it said cosign 2 was enough (it reports "no signatures found"), and the Kyverno example used the default Cosign type, which reads the tag and would reject every published image. Also switch the Kyverno example to the per-rule failureAction, drop the rekor URL the bundle path ignores, mention the Sigstore TUF egress the cluster needs, pin cosign in the Azure DevOps example, and replace the open question about AKS Image Integrity with what it actually supports: Notation signatures, Audit only, preview. Assisted-by: AI
The Kyverno, policy-controller and Azure DevOps snippets were checked against the projects' source and docs, not run in a real cluster or pipeline, so say so instead of presenting them as ready to deploy. Also name the releases that introduced signing, 6.2.12 and 5.4.39, so readers of an older version's documentation know where they stand. Assisted-by: AI
stevenvegt
requested review from
gerardsn,
reinkrul and
woutslakhorst
as code owners
September 17, 2026 08:46
reinkrul
approved these changes
Sep 17, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Backport of #4555 to V6.2. Cherry-picked without conflicts;
docs/pages/deployment/docker.rstis identical to master's on this branch.The signing job installs cosign-installer v4.1.2, which is cosign 3, and cosign 3 stores a signature as a Sigstore bundle attached through the OCI referrers API instead of the
sha256-<digest>.sigtag. The verification guide added with #4451 still described the cosign 2 world, so following it did not get you a verified image.What changed:
nutsfoundation/nuts-node:masterhas no.sigtag and one referrer withartifactType: application/vnd.dev.sigstore.bundle.v0.3+json; cosign 2.6.1 fails withno signatures found, cosign 3.1.3 verifies.type: SigstoreBundle. Without it Kyverno uses its defaultCosigntype, which reads the.sigtag and would reject every Nuts node image. Requires Kyverno 1.13 or later.rekor.urldropped (ignored on the bundle path, the trust root comes from Sigstore TUF) andspec.validationFailureActionreplaced by the per-rulefailureAction, which is the non-deprecated field.signatureFormat: bundleon the authority (0.14 or later).latest.Docs build with Sphinx without new warnings.