Integrate Keycloak with Sigstore for Secure Software Delivery

Your artifacts may be signed, but do you know who actually signed them? Many teams use Sigstore for keyless signing and Keycloak for identity. But when these systems aren't connected, it's hard to prove that every signature truly belongs to the right person or service. That weakens trust in the software supply chain. At KubeCon Japan, Oshi Gupta will show how to integrate Keycloak with Sigstore's keyless signing flow, so every signed artifact is cryptographically tied to a verified identity under your own control. The session also covers Fulcio configuration, identity claims, and real-world challenges you'll face in production. If you're building secure software delivery pipelines, don't miss this session. #KubeCon #KubeConJapan #Sigstore #Keycloak #SoftwareSupplyChain #DevSecOps #CloudNative

  • No alternative text description for this image

Excited for Japan to get insights from Oshi Gupta. She's a wealth of knowledge!

To view or add a comment, sign in

Explore content categories