0Pricing
Helm Academy · Lesson

Keyless Signing with Sigstore Cosign

Signing OCI charts without managing GPG keys.

The Trouble With GPG Keys

Classic provenance means managing long-lived GPG keys: storing them, rotating them, distributing public keys. Sigstore offers a lighter path.

Meet Cosign

Cosign, part of the Sigstore project, signs container images and OCI artifacts. Helm charts pushed to OCI registries are exactly such artifacts.

All lessons in this course

  1. What a Provenance File Guarantees
  2. Signing a Chart with helm package --sign
  3. Verifying with helm verify and --verify
  4. Keyless Signing with Sigstore Cosign
← Back to Helm Academy