Skip to content

docs: correct Docker image verification instructions for cosign 3 (backport #4555 to V6.2) - #4556

Merged
stevenvegt merged 2 commits into
V6.2from
V6_2/backport-4555-cosign-v3-docs
Sep 18, 2026
Merged

stevenvegt merged 2 commits into
V6.2from
V6_2/backport-4555-cosign-v3-docs

Conversation

@stevenvegt

Copy link
Copy Markdown
Member

Backport of #4555 to V6.2. Cherry-picked without conflicts; docs/pages/deployment/docker.rst is identical to master's on this branch.

The signing job installs cosign-installer v4.1.2, which is cosign 3, and cosign 3 stores a signature as a Sigstore bundle attached through the OCI referrers API instead of the sha256-<digest>.sig tag. The verification guide added with #4451 still described the cosign 2 world, so following it did not get you a verified image.

What changed:

  • cosign 3.0 or later is required, and the docs explain the bundle format. Checked against the published image: nutsfoundation/nuts-node:master has no .sig tag and one referrer with artifactType: application/vnd.dev.sigstore.bundle.v0.3+json; cosign 2.6.1 fails with no signatures found, cosign 3.1.3 verifies.
  • The Kyverno example gets type: SigstoreBundle. Without it Kyverno uses its default Cosign type, which reads the .sig tag and would reject every Nuts node image. Requires Kyverno 1.13 or later.
  • rekor.url dropped (ignored on the bundle path, the trust root comes from Sigstore TUF) and spec.validationFailureAction replaced by the per-rule failureAction, which is the non-deprecated field.
  • policy-controller needs signatureFormat: bundle on the authority (0.14 or later).
  • AKS Image Integrity cannot check a cosign signature: Notation is its only verifier, Audit its only effect, and it is a preview that Microsoft says not to use in production. The docs say that instead of leaving it open.
  • The Azure DevOps snippet pins a cosign 3 version rather than downloading latest.
  • A short paragraph says the enforcement examples are a starting point: they were checked against the projects' sources and docs, not run in a real cluster or pipeline.
  • The note names the releases that introduce signing, 6.2.12 and 5.4.39.

Docs build with Sphinx without new warnings.

The signing job runs cosign 3, which stores a signature as a Sigstore
bundle attached through the OCI referrers API instead of the
sha256-<digest>.sig tag. The verification guide still described the
cosign 2 layout: it said cosign 2 was enough (it reports "no signatures
found"), and the Kyverno example used the default Cosign type, which
reads the tag and would reject every published image.

Also switch the Kyverno example to the per-rule failureAction, drop the
rekor URL the bundle path ignores, mention the Sigstore TUF egress the
cluster needs, pin cosign in the Azure DevOps example, and replace the
open question about AKS Image Integrity with what it actually supports:
Notation signatures, Audit only, preview.

Assisted-by: AI
The Kyverno, policy-controller and Azure DevOps snippets were checked
against the projects' source and docs, not run in a real cluster or
pipeline, so say so instead of presenting them as ready to deploy.

Also name the releases that introduced signing, 6.2.12 and 5.4.39, so
readers of an older version's documentation know where they stand.

Assisted-by: AI
@stevenvegt
stevenvegt merged commit bcab65f into V6.2 Sep 18, 2026
8 checks passed
@stevenvegt
stevenvegt deleted the V6_2/backport-4555-cosign-v3-docs branch September 18, 2026 07:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants