---
title: "SLSA Level 3 Cryptographic Software Supply Chain | Zero-Trust Architecture Canon"
description: "Tamper-proof software supply chain architecture adhering to SLSA Level 3, featuring ephemeral build runners, Cosign keyless image signing via Fulcio/Rekor, and strict Kubernetes admission gates."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_architectures_og.jpg"
canonicalUrl: "https://tinycto.tv/zero-trust/architectures/slsa-l3-sigstore-provenance"
locale: "en"
---

# SLSA Level 3 Cryptographic Software Supply Chain (`zt-arch-06`)

> **Pillar**: APPLICATIONS_WORKLOADS | **Archetype**: SUPPLY_CHAIN_PROVENANCE
> **Blocked MITRE ATT&CK Techniques**: T1195.001, T1195.002, T1554, T1059

## Architecture Summary

Tamper-proof software supply chain architecture adhering to SLSA Level 3, featuring ephemeral build runners, Cosign keyless image signing via Fulcio/Rekor, and strict Kubernetes admission gates.

## Adversary Model

Adversary breaches developer account or build environment, injecting malicious backdoors into compiled release binaries.

## NIST SP 800-207 Core Tenets

- The enterprise monitors and measures the integrity and security posture of all owned and associated assets.
- No asset is inherently trusted; the enterprise evaluates the asset security posture before admitting workloads.

## 3-Tier Maturity Configurations

### INITIAL Maturity Target

- **Implementation Scope**: Container images signed with private GPG key stored in CI secrets.
- **Authentication Enforcement**: Manual verification of signatures in release deployment scripts.
- **Network Isolation**: Standard public registry pulling.

### ADVANCED Maturity Target

- **Implementation Scope**: Keyless signing with Sigstore (Fulcio OIDC + Rekor transparency log) and in-toto attestations.
- **Authentication Enforcement**: Kubernetes Kyverno admission policy enforcing valid signature and vulnerability scan.
- **Network Isolation**: Private mirrored registry with immutable image tags.

### OPTIMAL Maturity Target

- **Implementation Scope**: End-to-end SLSA Level 3 hermetic builds on isolated ephemeral runners with verifiable SBOMs.
- **Authentication Enforcement**: Admission gate verifying provenance, source commit hash, builder identity, and zero CVEs.
- **Network Isolation**: Hermetic build environments with zero internet access during compilation phase.

## Terraform HCL Manifest

```hcl
resource "helm_release" "kyverno" {
  name       = "kyverno"
  repository = "https://kyverno.github.io/kyverno/"
  chart      = "kyverno"
  namespace  = "kyverno"

  set {
    name  = "admissionController.replicas"
    value = "3"
  }
}
```

## Kubernetes / Tetragon Policy Manifest

```yaml
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
  name: verify-image-signature
spec:
  validationFailureAction: Enforce
  rules:
  - name: verify-sigstore
    match:
      any:
      - resources:
          kinds:
          - Pod
    verifyImages:
    - imageReferences:
      - "ghcr.io/tiny-cto/*"
      attestors:
      - entries:
        - keyless:
            subject: "https://github.com/tiny-cto/tinycto-tv/.github/workflows/docker-build.yml@refs/heads/main"
            issuer: "https://token.actions.githubusercontent.com"
```


```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "SLSA Level 3 Cryptographic Software Supply Chain | Zero-Trust Architecture Canon",
  "description": "Tamper-proof software supply chain architecture adhering to SLSA Level 3, featuring ephemeral build runners, Cosign keyless image signing via Fulcio/Rekor, and strict Kubernetes admission gates.",
  "url": "https://tinycto.tv/zero-trust/architectures/slsa-l3-sigstore-provenance"
}
```
