---
title: "SLSA Level 3 Cryptographic Software Supply Chain | Zero-Trust Architecture Canon"
description: "Konteyner ve kod bütünlüğünü güvenceye alan, SLSA Seviye 3 uyumlu, Cosign anahtarsız imzalama ve Kubernetes kabul denetleyicileri (Kyverno) ile çalışan kriptografik tedarik zinciri mimarisi."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_architectures_og.jpg"
canonicalUrl: "https://tinycto.tv/tr/zero-trust/architectures/slsa-l3-sigstore-provenance"
locale: "tr"
---

# SLSA Level 3 Cryptographic Software Supply Chain (`zt-arch-06`)

> **Sütun**: APPLICATIONS_WORKLOADS | **Arketip**: SUPPLY_CHAIN_PROVENANCE
> **Engellenen MITRE ATT&CK Teknikleri**: T1195.001, T1195.002, T1554, T1059

## Mimari Özeti

Konteyner ve kod bütünlüğünü güvenceye alan, SLSA Seviye 3 uyumlu, Cosign anahtarsız imzalama ve Kubernetes kabul denetleyicileri (Kyverno) ile çalışan kriptografik tedarik zinciri mimarisi.

## Saldırgan Modeli

Saldırganın geliştirici hesabını veya derleme sunucusunu ele geçirerek üretim ikili dosyalarına arka kapı yerleştirmesi.

## NIST SP 800-207 Temel İlkeleri

- The enterprise monitors and measures the integrity and security posture of all owned and associated assets.
- No asset is inherently trusted; the enterprise evaluates the asset security posture before admitting workloads.

## 3 Kademeli Olgunluk Yapılandırmaları

### INITIAL Seviyesi

- **Uygulama Kapsamı**: Container images signed with private GPG key stored in CI secrets.
- **Kimlik Doğrulama Zorlaması**: Manual verification of signatures in release deployment scripts.
- **Ağ İzolasyonu**: Standard public registry pulling.

### ADVANCED Seviyesi

- **Uygulama Kapsamı**: Keyless signing with Sigstore (Fulcio OIDC + Rekor transparency log) and in-toto attestations.
- **Kimlik Doğrulama Zorlaması**: Kubernetes Kyverno admission policy enforcing valid signature and vulnerability scan.
- **Ağ İzolasyonu**: Private mirrored registry with immutable image tags.

### OPTIMAL Seviyesi

- **Uygulama Kapsamı**: End-to-end SLSA Level 3 hermetic builds on isolated ephemeral runners with verifiable SBOMs.
- **Kimlik Doğrulama Zorlaması**: Admission gate verifying provenance, source commit hash, builder identity, and zero CVEs.
- **Ağ İzolasyonu**: Hermetic build environments with zero internet access during compilation phase.

## Terraform HCL Manifest

```hcl
resource "helm_release" "kyverno" {
  name       = "kyverno"
  repository = "https://kyverno.github.io/kyverno/"
  chart      = "kyverno"
  namespace  = "kyverno"

  set {
    name  = "admissionController.replicas"
    value = "3"
  }
}
```

## Kubernetes / Tetragon Policy Manifest

```yaml
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
  name: verify-image-signature
spec:
  validationFailureAction: Enforce
  rules:
  - name: verify-sigstore
    match:
      any:
      - resources:
          kinds:
          - Pod
    verifyImages:
    - imageReferences:
      - "ghcr.io/tiny-cto/*"
      attestors:
      - entries:
        - keyless:
            subject: "https://github.com/tiny-cto/tinycto-tv/.github/workflows/docker-build.yml@refs/heads/main"
            issuer: "https://token.actions.githubusercontent.com"
```


```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "SLSA Level 3 Cryptographic Software Supply Chain | Zero-Trust Architecture Canon",
  "description": "Konteyner ve kod bütünlüğünü güvenceye alan, SLSA Seviye 3 uyumlu, Cosign anahtarsız imzalama ve Kubernetes kabul denetleyicileri (Kyverno) ile çalışan kriptografik tedarik zinciri mimarisi.",
  "url": "https://tinycto.tv/tr/zero-trust/architectures/slsa-l3-sigstore-provenance"
}
```
