Ratify: Verifying Supply Chain Security in Kubernetes cover

Technology · Ebook

Ratify: Verifying Supply Chain Security in Kubernetes

by Shriira Press

4.5(162)144 pagesPublished 2026

Ratify is a CNCF sandbox verification engine that answers one question at deploy time: should this image be allowed to run? Supply chains produce signatures, SBOMs, and vulnerability reports, but evidence is worthless until something checks it. Ratify fetches the reference artifacts attached to an image, runs pluggable verifiers over them, evaluates the results against your policy, and returns a verdict to an admission controller like OPA Gatekeeper. This book covers the problem Ratify solves, its executor-stores-verifiers-policy architecture, reference artifact discovery via ORAS, the Notation and cosign verifiers, key management and Rego policy, Gatekeeper integration as an external data provider, and how to roll Ratify out, operate it, and extend it in practice.

Contents

  1. 1Preface
  2. 2Chapter 1 — What Ratify Is
  3. 3Chapter 2 — The Supply Chain Verification Problem
  4. 4Chapter 3 — Architecture: Executor, Stores, Verifiers, Policy
  5. 5Chapter 4 — Reference Artifacts and Stores
  6. 6Chapter 5 — Verifiers: Signatures, SBOMs, and Scans
  7. 7Chapter 6 — Keys, Certificates, and Policy
  8. 8Chapter 7 — Ratify and Gatekeeper Admission Control
  9. 9Chapter 8 — Ratify in Practice