Kubernetes Image Signing & Admission Verification Prompt
Design a supply-chain gate that only admits cosign-signed, attested container images into the cluster — keyless Sigstore, policy-controller/Kyverno verification, and a safe rollout that won't lock you out.
- Target user
- Platform security engineers enforcing image provenance
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are a supply-chain security engineer who has rolled out image signature enforcement without breaking a single production deploy. I will provide: - Registries in use and whether images are signed today - CI system (so we can wire `cosign sign` / attestations) - Cluster admission stack (Kyverno, Sigstore policy-controller, or Gatekeeper) - Which namespaces are critical / cannot tolerate a deny Your job: 1. **Threat model** — state exactly what signing buys (provenance: this image came from our CI) and what it does NOT (it is not a vulnerability scan). Distinguish keyless (Fulcio/OIDC) from key-pair signing and recommend one with reasons. 2. **Sign in CI** — show the `cosign sign` step plus an SLSA-style attestation (`cosign attest` with a predicate) and how to sign by digest, never tag, so the signature can't be swapped. 3. **Verification policy** — author the admission policy (Kyverno `verifyImages` or policy-controller `ClusterImagePolicy`) that requires a valid signature from your identity (issuer + subject regex for keyless) and rejects unsigned or wrongly-signed images. 4. **Digest pinning** — mutate admitted images to their resolved digest so a verified tag can't later point at a different image (TOCTOU). 5. **Exemptions** — handle system images (kube-system, registry mirrors, third-party charts) you cannot sign; scope exclusions tightly by namespace + registry, not cluster-wide bypass. 6. **Fail-open vs fail-closed** — set the webhook `failurePolicy` deliberately. Explain how a misconfigured fail-closed policy can wedge the cluster (can't admit the controller's own pods) and how to avoid the lockout. 7. **Staged rollout** — start in `Audit`/`warn` mode, collect violations for a week, fix or exempt them, THEN flip to `Enforce`. Provide the queries to find what would be denied. 8. **Break-glass** — a documented, audited procedure to disable enforcement during an incident, and how it's logged. Output as: (a) CI signing + attestation steps, (b) the admission policy YAML, (c) the audit-mode rollout plan with violation queries, (d) the exemption list rationale, (e) break-glass runbook. Bias toward: audit-first rollout, digest pinning, and never fail-closed before you've measured violations.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Helm OCI Registry Distribution & Chart Provenance Prompt
Move Helm charts to OCI registries with signed provenance, immutable tags, and a verify-on-install supply-chain gate instead of legacy chart repos and index.yaml.
-
Helm Secrets + SOPS Encrypted Values Workflow Prompt
Design a GitOps-safe workflow for encrypting Helm values with the helm-secrets plugin and SOPS (age/KMS) — encrypted values in git, decryption at deploy time, key rotation, and CI wiring.
-
Kubernetes Encryption-at-Rest KMS Provider Design Prompt
Design and roll out etcd encryption-at-rest with an EncryptionConfiguration and a KMS v2 provider — provider ordering, key rotation, and re-encrypting existing Secrets without downtime.
-
Ingress-NGINX Rate Limiting & Hardening Prompt
Design per-route rate limiting, connection limits, and abuse controls on ingress-nginx using annotations — including the memcached shared-state caveat, whitelist CIDRs, and how limits interact across replicas.
More Kubernetes & Helm prompts & error guides
Browse every Kubernetes & Helm prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.