{"repo":"sse-secure-systems/connaisseur","free":true,"listed":false,"github":"https://github.com/sse-secure-systems/connaisseur","clone":"git clone https://github.com/sse-secure-systems/connaisseur.git","description":"An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster","language":"Go","stars":477,"topics":["kubernetes","integrity","docker","docker-content-trust","signature-verification","authentication","cosign","security","provenance","container"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"A Kubernetes admission controller to integrate container image signature verification and trust pinning into a cluster. :point right: The full documentation is available here :book: What is Connaisseur? Connaisseur ensures integrity and provenance of container images in a Kubernetes cluster. To do so, it intercepts resource creation or update requests sent to the Kubernetes cluster, identifies all container images and verifies their signatures against pre-configured public keys. Based on the result, it either accepts or denies those requests. Connaisseur is developed under three core values: Security , Usability , Compatibility . It is built to be extendable and currently aims to support the following signing solutions: - Notary / Docker Content Trust - Sigstore / Cosign - Notation It provides several additional features such as: - Alerting: send alerts based on verification result - Detection Mode: warn but do not block invalid images - Namespaced Validation: restrict validation to dedicated namespaces Quick start Getting started to verify image signatures is only a matter of minutes: :warning: Only try this out on a test cluster as deployments with unsigned images will be blocked. :warning: Connaisseur comes pre-configured with public keys for its own repository and Docker's official images (official images can be found here). It can be fully configured via helm/values.yaml . For a quick start, clone the Connaisseur repository: Next, install Connaisseur via Helm: Once insta","default_branch":null,"files":null,"tree":[],"storefront":"/r/sse-secure-systems","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/sse-secure-systems/connaisseur/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}