Sigstore Foundation is an intensive one-day, hands-on course. It gives working technology professionals a comprehensive introduction to Sigstore, the Open Source Security Foundation project. Sigstore underpins many modern software supply chain security workflows. Attendees leave with a clear understanding of Sigstore’s principal features and use cases. They also learn the role it plays alongside broader initiatives such as SLSA and FRSCA.
The day opens with a Sigstore overview, introducing Fulcio for issuing short-lived signing certificates. It also covers Rekor, the public transparency log that records every signature. Students then sign artifacts keylessly with Cosign. This ties each signature to an OIDC identity instead of a long-lived private key that has to be stored, rotated, and protected from theft. This keyless model removes a common weak point in traditional signing workflows. A leaked key can undermine trust in every artifact it ever signed.
Attendees next verify signed artifacts and In-toto attestations against the Rekor transparency log. This confirms provenance before an artifact is trusted and gives reviewers an auditable record of who signed what and when. The course closes with Kubernetes policy control, where students configure the Kubernetes policy controller. This controller enforces signature and attestation requirements before a workload is admitted to the cluster, blocking unsigned or unverified images from ever reaching production. Keyless signing, verification, key management, and general best practices are covered in class and reinforced through lab exercises that mirror real CI/CD pipeline integrations. Upon completion, attendees have the skills and information necessary to begin using Sigstore in a production environment.
Who Should Attend
Developers, IT and QA Staff, Technical Managers, SRE, DevOps/DevSecOps and Build personnel
What Attendees Will Learn
Upon completing Sigstore Foundation, attendees will be able to:
- Explain the Sigstore framework and its role in software supply chain security
- Sign artifacts keylessly using Cosign
- Verify signed artifacts and attestations
- Apply Kubernetes policy control using Sigstore components
Prerequisites
Students should have taken the RX-M “Kubernetes Foundation” course or have equivalent knowledge including some experience with Linux and Linux containers.