Keycloak + Sigstore: Binding Human Identity To Artifact Signatures - Oshi Gupta & Sagar Utekar

CNCF
AI summary

This talk demonstrates how to integrate Keycloak as the OIDC provider for Sigstore's keyless signing flow, enabling organizations to bind artifact signatures to human and service identities managed in their own identity infrastructure rather than third-party providers like GitHub or Google. Covers Fulcio configuration, Keycloak realm and client setup, and addresses operational challenges including token expiry during long builds, claim mapping issues, and service identity handling for automated pipelines. For DevOps engineers and security teams implementing software supply chain security.