Keycloak + Sigstore: Binding Human Identity To Artifact Signatures - Oshi Gupta & Sagar Utekar
Keycloak Sigstore Fulcio Oidc Container signing Software supply chain Artifact security Keyless signing Cloud native security Identity management
This talk demonstrates how to integrate Keycloak as the OIDC provider for Sigstore's keyless signing flow, enabling organizations to bind artifact signatures to human and service identities managed in their own identity infrastructure rather than third-party providers like GitHub or Google. Covers Fulcio configuration, Keycloak realm and client setup, and addresses operational challenges including token expiry during long builds, claim mapping issues, and service identity handling for automated pipelines. For DevOps engineers and security teams implementing software supply chain security.