---
title: "Chapter 05: Software Supply Chain Defense: SLSA L3, Cosign & Kyverno | TinyCTO Zero-Trust Canon"
description: "Constructing an unbreachable software delivery pipeline. Keyless container image signing with Sigstore Cosign, Fulcio OIDC, Rekor transparency logs, and Kubernetes Kyverno admission policy enforcement."
image: "https://tinycto.tv/assets/zero-trust/zero_trust_manuals_og.jpg"
canonicalUrl: "https://tinycto.tv/zero-trust/manuals/05-supply-chain-security-slsa-sigstore"
locale: "en"
---

# Chapter 05: Software Supply Chain Defense: SLSA L3, Cosign & Kyverno

> **Canonical Zero-Trust Engineering Field Manual**
> **Read Time**: 24 min read | **Maturity**: OPTIMAL | **NIST SP 800-207**: NIST SP 800-207 Tenet 5

## Executive Summary

Constructing an unbreachable software delivery pipeline. Keyless container image signing with Sigstore Cosign, Fulcio OIDC, Rekor transparency logs, and Kubernetes Kyverno admission policy enforcement.

## Chapter Content

# Software Supply Chain Defense: SLSA L3, Cosign & Kyverno

## The Software Supply Chain Threat
Modern software delivery pipelines are prime targets for nation-state adversaries. Attacking the build system or package repository allows adversaries to inject malicious code into trusted downstream artifacts (e.g. SolarWinds, Codecov).

## SLSA Framework (Supply-chain Levels for Software Artifacts)
- **SLSA Level 1:** Documented build process with provenance generated.
- **SLSA Level 2:** Hosted build platform with authenticated provenance signatures.
- **SLSA Level 3:** Isolated, hermetic build environments preventing external tampering during compilation, with tamper-evident cryptographic provenance.

## Keyless Signing with Sigstore Cosign
Instead of managing private GPG keys, Sigstore Cosign uses **keyless signing**:
1. The CI workflow initiates an OIDC handshake with Fulcio CA.
2. Fulcio issues a short-lived (10-minute) X.509 certificate binding the builder's identity to an ephemeral key pair.
3. Cosign signs the container image and records the signature in the **Rekor** immutable transparency log.
4. Kubernetes Kyverno admission controllers verify the signature before any container is permitted to run.

```yaml
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
  name: verify-signed-images
spec:
  validationFailureAction: Enforce
  rules:
    - name: verify-sigstore-signature
      match:
        resources:
          kinds:
            - Pod
      verifyImages:
        - imageReferences:
            - "ghcr.io/tiny-cto/*"
          attestors:
            - entries:
                - keyless:
                    issuer: "https://token.actions.githubusercontent.com"
                    subject: "https://github.com/tiny-cto/tinycto-tv/.github/workflows/*"
```


### Canonical Links & Cross References

- **Manuals Library**: https://tinycto.tv/zero-trust/manuals
- **18 Reference Architectures**: https://tinycto.tv/zero-trust/architectures
- **Posture Assessor Wizard**: https://tinycto.tv/zero-trust/wizard
- **Security Tooling Matrix**: https://tinycto.tv/zero-trust/matrix

```json
{
  "@context": "https://schema.org",
  "@type": "TechArticle",
  "headline": "Chapter 05: Software Supply Chain Defense: SLSA L3, Cosign & Kyverno | TinyCTO Zero-Trust Canon",
  "description": "Constructing an unbreachable software delivery pipeline. Keyless container image signing with Sigstore Cosign, Fulcio OIDC, Rekor transparency logs, and Kubernetes Kyverno admission policy enforcement.",
  "url": "https://tinycto.tv/zero-trust/manuals/05-supply-chain-security-slsa-sigstore",
  "inLanguage": "en"
}
```
