The Airgap Native Packager Manager for Kubernetes
-
Updated
Nov 11, 2025 - Go
The Airgap Native Packager Manager for Kubernetes
Remove all the resources from an AWS account
An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster
Compage - Low-Code Framework to develop Rest API, gRPC, dRPC, GraphQL, WebAssembly, microservices, FaaS, Temporal workloads, IoT and edge services, K8s controllers, K8s CRDs, K8s custom APIs, K8s Operators, K8s hooks, etc. with minimal coding and by automatically applying best practice methods like software supply chain security measures, SBOM, …
This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)
Integrates Spiffe and Vault to have secretless authentication
Example goreleaser + github actions config with keyless signing, SBOM generation, and attestations
Sigstore Homebrew Tap
Sign your artifacts, source code or container images using Sigstore tools, Save the Signatures you want to use, and Validate & Control the deployments to allow only the known Sources based on Signatures, Maintainers & other payloads automatically.
Example code repo for blog post https://chainguard.dev/posts/2022-01-07-cosign-aws-codepipeline
This GitHub Action use kaniko and Amazon Linux container with nitro-cli to build a reproducible AWS Nitro Enclaves EIF file and its information.
Cosign CircleCI orb. To learn more about cosign visit the GitHub repo
Docker Registry Authentication Made Simple
Add a description, image, and links to the cosign topic page so that developers can more easily learn about it.
To associate your repository with the cosign topic, visit your repo's landing page and select "manage topics."