APURV
  • Home
  • Journey
  • Projects
  • Blogs
  • Interview
  • Exams
Resume
APURV

Building scalable, secure, and production-ready cloud infrastructure. Automation first.

NAVIGATION

HomeExperienceProjectsCertificationsSkills

TECH STACK

AWSGCPK8sCI/CDLinuxDocker

CONNECT

LinkedInGitHubEmailResume

© 2026 Apurv Gujjar. All rights reserved.
Apurv Gujjar
Apurv GujjarDevOps & Cloud Engineer
|Interview Documentation
Portfolio
Handbooks
🎯Linux🐙Git & GitHub🤖GitHub Actions🌐Networking☁AWS🛠Terraform🐳Docker☸Kubernetes📊Monitoring🛡DevSecOps💰Cost Optimization🚨Incident Scenarios👤HR & Behavioral☁GCP🐍Python
Interview DocumentationGitHub ActionsHow do you sign build artifacts or container images within a GitHub Actions run to verify their authenticity?
Back to all GitHub Actions questions
Q21

How do you sign build artifacts or container images within a GitHub Actions run to verify their authenticity?

💬Answer

Use Cosign (from Sigstore) to sign container images using GitHub's OIDC identity:

  1. Authenticate to AWS/GCP using OIDC to fetch short-lived registry credentials.
  2. Build and push the Docker image to your container registry.
  3. Install Cosign in the runner workflow.
  4. Run cosign sign --yes <image-digest> utilizing keyless signing. Cosign validates the runner's OIDC JWT identity and records the signature in the Sigstore transparency log (Rekor).

Related GitHub Actions Questions

View All GitHub ActionsQuestions →
Q1

What is GitHub Actions, and how does it process workflows under the hood?

Q2

Can you list and explain the key architectural components of GitHub Actions?

Q3

How do you configure workflow triggers, and what is the syntax for defining manual execution parameters?

Q4

What is a matrix strategy in GitHub Actions, and in what scenarios would you use it?

Apurv Gujjar - DevOps & Cloud Engineer
Created by

Apurv Gujjar

DevOps & Cloud Engineer

Specialized in:DevOpsAWSGCPKubernetesTerraformDocker
View Portfolio