Skip to main content
Redhat Developers  Logo
  • Products

    Platforms

    • Red Hat Enterprise Linux
      Red Hat Enterprise Linux Icon
    • Red Hat AI
      Red Hat AI
    • Red Hat OpenShift
      Openshift icon
    • Red Hat Ansible Automation Platform
      Ansible icon
    • View All Red Hat Products

    Featured

    • Red Hat build of OpenJDK
    • Red Hat Developer Hub
    • Red Hat JBoss Enterprise Application Platform
    • Red Hat OpenShift Dev Spaces
    • Red Hat OpenShift Local
    • Red Hat Developer Sandbox

      Try Red Hat products and technologies without setup or configuration fees for 30 days with this shared Openshift and Kubernetes cluster.
    • Try at no cost
  • Technologies

    Featured

    • AI/ML
      AI/ML Icon
    • Linux
      Linux Icon
    • Kubernetes
      Cloud icon
    • Automation
      Automation Icon showing arrows moving in a circle around a gear
    • View All Technologies
    • Programming Languages & Frameworks

      • Java
      • Python
      • JavaScript
    • System Design & Architecture

      • Red Hat architecture and design patterns
      • Microservices
      • Event-Driven Architecture
      • Databases
    • Developer Productivity

      • Developer productivity
      • Developer Tools
      • GitOps
    • Automated Data Processing

      • AI/ML
      • Data Science
      • Apache Kafka on Kubernetes
    • Platform Engineering

      • DevOps
      • DevSecOps
      • Ansible automation for applications and services
    • Secure Development & Architectures

      • Security
      • Secure coding
  • Learn

    Featured

    • Kubernetes & Cloud Native
      Openshift icon
    • Linux
      Rhel icon
    • Automation
      Ansible cloud icon
    • AI/ML
      AI/ML Icon
    • View All Learning Resources

    E-Books

    • GitOps Cookbook
    • Podman in Action
    • Kubernetes Operators
    • The Path to GitOps
    • View All E-books

    Cheat Sheets

    • Linux Commands
    • Bash Commands
    • Git
    • systemd Commands
    • View All Cheat Sheets

    Documentation

    • Product Documentation
    • API Catalog
    • Legacy Documentation
  • Developer Sandbox

    Developer Sandbox

    • Access Red Hat’s products and technologies without setup or configuration, and start developing quicker than ever before with our new, no-cost sandbox environments.
    • Explore Developer Sandbox

    Featured Developer Sandbox activities

    • Get started with your Developer Sandbox
    • OpenShift virtualization and application modernization using the Developer Sandbox
    • Explore all Developer Sandbox activities

    Ready to start developing apps?

    • Try at no cost
  • Blog
  • Events
  • Videos

Red Hat Trusted Artifact Signer Tech Preview 2

February 27, 2024
Markus Nagel

Share:

    In November 2023, we announced the Tech Preview of Red Hat Trusted Artifact Signer, outlining the need for a production-ready deployment of the Sigstore project, its benefits and core use cases in the software supply chain. 

    Red Hat Trusted Artifact Signer introduces keyless signing and verification, binding the signature origin to a verifiable OIDC Authentication identity instead of a long-lived key pair that needs to be managed, distributed and revoked/renewed. This significantly reduces management overhead and simplifies the usage of a signing and verification infrastructure throughout your Software Supply Chain.

    Today, we are excited to announce the Tech Preview 2 of Red Hat Trusted Artifact Signer that has seen a lot of enhancements since that first Tech Preview release, based on your feedback! We want to say thank you for your feedback via rhtas-support@redhat.com , which directly helps us shape the priorities on the way to GA (general availability) of Red Hat Trusted Artifact Signer.

     

    To name just a few highlights:

     

    1. We are now using an Operator-based installation
    2. You can now easily configure your own OIDC provider (with documentation for Keycloak and Google available, more to come)
    3. Enterprise Contract (EC) binaries have been included - to verify build provenance, SLSA compliance and much, much more.
    Enterprise Contract Logo

     

    Installation

    The biggest change is undoubtedly the introduction of an Operator-based install procedure.

    The first Tech Preview was based on a Helm Chart Installation, supported by install scripts. This procedure has been simplified by providing an Operator, available from Red Hat Operator Hub.

    As you might expect, the Operator-based installation is straightforward and takes care of all the components required to run Red Hat Trusted Artifact Signer.

    Red Hat Trusted Artifact Signer on OperatorHub
    Red Hat Trusted Artifact Signer on OperatorHub

     

    Red Hat Trusted Artifact Signer Operator Details
    Red Hat Trusted Artifact Signer Operator Details showing all managed components

     

    OIDC Authentication Provider

    The install script used for the first tech preview of Red Hat Trusted Artifact Signer (and the corresponding Helm Charts) included the installation of a Keycloak instance - changing that to a different OIDC provider required some modification of the Chart and its values files. 

    Taking into account that many of you will already have OIDC providers deployed, the operator install does not automatically install Keycloak alongside the Red Hat Trusted Artifact Signer components.


    If you prefer to continue using the default Keycloak setup that was part of the first tech preview, you can leverage this simple install guide (based on the Red Hat SSO Operator) after cloning (or downloading) https://github.com/securesign/sigstore-ocp/tree/release-1.0.gamma 

    oc apply --kustomize keycloak/operator/base
    
    oc get keycloaks -A
    # wait for this command to succeed (it won’t show any “keycloaks” 
    # but if it doesn’t generate an error, it means the Keycloak CRDs 
    # have successfully been registered)
    
    oc apply --kustomize keycloak/resources/base
    # wait for keycloak-system pods to be running before proceeding
    

    This will install the default Keycloak instance with test user “jdoe@redhat.com” and password “secure” that was used in the first tech preview release.

    There is also documentation on how to use Google as your OIDC provider, with more providers to come. [Oh, by the way - you can use more than one authentication provider and use different providers with the same Trusted Artifact Signer instance, based on your use case - it’s all outlined in the documentation]
     

    Using Enterprise Contract

    Enterprise Contract enables users (typically via pipelines) to securely verify supply chain artifacts, and enforce policies about how they were built and tested, in a manageable, scalable, and declarative way. 


    Enterprise Contract and Red Hat Trusted Artifact Signer have always been close friends, since both cater to securing the software supply chain and Enterprise Contract can leverage all the advantages of a keyless signing and verification infrastructure. With the release of the second tech preview of Red Hat Trusted Artifact Signer, the Enterprise Contract ec binary is now shipped with the Red Hat Trusted Artifact Signer installation and an example is provided on how to verify SLSA provenance of a container image using Enterprise Contract.


    You can download the ec binary (for your workstation, or to include it in your software delivery toolchain of choice) via the Red Hat OpenShift UI:

    CLI Tools Menu
    Open the CLI tools page
    ec CLI command
    ec CLI downloads have been added

     

    In this example from the Red Hat Trusted Artifact Signer deployment guide, you can see how to verify the provenance attestation linked to a container image (in other words - who has built this image, was the build pipeline in accordance with common/required standards, and much much more):
     

    CLI showing image signature and attestations
    "cosign tree" shows the image, attached signatures and attestations

     

    Validating the image and attestations associated with it:

    ec validate image --image quay.io/mnagel/backstage-test:latest \
    --certificate-identity-regexp 'jdoe@redhat.com' \
    --certificate-oidc-issuer-regexp 'keycloak-keycloak-system' \
    --rekor-url $REKOR_REKOR_SERVER \
    --output yaml --show-successes --info
    result snippet showing ec validation success
    ec validation checks and success

     

    In addition to these basic checks, Enterprise Contract enables your pipelines to apply policies to validation results, either from the current kubernetes context or inline - for further information, make sure to check the “ec validate image” command line options and some further examples of policies.

    Note: This is only an example - in real life, the attestation should come from the build system itself (e.g. via Tekton Chains) and should not be an arbitrary hand-crafted provenance file. However, this example shows how an attestation is signed and attached to an image and verified via Enterprise Contract, allowing for verification and application of policies.

    To provide us with additional feedback, please contact rhtas-support@redhat.com 

     

     

     

    Last updated: February 29, 2024
    Disclaimer: Please note the content in this blog post has not been thoroughly reviewed by the Red Hat Developer editorial team. Any opinions expressed in this post are the author's own and do not necessarily reflect the policies or positions of Red Hat.

    Recent Posts

    • How to modify system-reserved parameters on OpenShift nodes

    • The odo CLI is deprecated: What developers need to know

    • Exposing OpenShift networks using BGP

    • Camel integration quarterly digest: Q3 2025

    • How to run I/O workloads on OpenShift Virtualization VMs

    Red Hat Developers logo LinkedIn YouTube Twitter Facebook

    Platforms

    • Red Hat AI
    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    • See all products

    Build

    • Developer Sandbox
    • Developer Tools
    • Interactive Tutorials
    • API Catalog

    Quicklinks

    • Learning Resources
    • E-books
    • Cheat Sheets
    • Blog
    • Events
    • Newsletter

    Communicate

    • About us
    • Contact sales
    • Find a partner
    • Report a website issue
    • Site Status Dashboard
    • Report a security problem

    RED HAT DEVELOPER

    Build here. Go anywhere.

    We serve the builders. The problem solvers who create careers with code.

    Join us if you’re a developer, software engineer, web designer, front-end designer, UX designer, computer scientist, architect, tester, product manager, project manager or team lead.

    Sign me up

    Red Hat legal and privacy links

    • About Red Hat
    • Jobs
    • Events
    • Locations
    • Contact Red Hat
    • Red Hat Blog
    • Inclusion at Red Hat
    • Cool Stuff Store
    • Red Hat Summit
    © 2025 Red Hat

    Red Hat legal and privacy links

    • Privacy statement
    • Terms of use
    • All policies and guidelines
    • Digital accessibility

    Report a website issue