Keycloak + Sigstore: Binding Human Identity To Artifact Signatures - Oshi Gupta & Sagar Utekar @cncf
Keycloak + Sigstore: Binding Human Identity To Artifact Signatures - Oshi Gupta & Sagar Utekar  @cncf
Uploaded August 2026 | Updated September 2026, 2 weeks ago
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io

Keycloak + Sigstore: Binding Human Identity To Artifact Signatures - Oshi Gupta, Improving Pune (Infracloud Technologies) & Sagar Utekar, Crowdstrike

Most teams treat signing and identity as two separate problems. Sigstore handles your artifact signatures. Keycloak handles your users. Nobody asks whether the person who triggered that signed build is actually who the signature claims they are.

That gap matters more than people realize.

In this talk we will walk through how we wired Keycloak directly into Sigstore's keyless signing flow as the OIDC provider — so every artifact signature is cryptographically bound to a verified human or service identity that lives in your own identity infrastructure, not GitHub's, not Google's. Your keys, your trust root, your audit trail.

We'll cover the exact Fulcio configuration that makes this work, how Keycloak realm and client setup maps to Sigstore's identity claims, and the operational realities nobody documents — token expiry during long builds, claim mapping mismatches that silently break verification, and how to handle service identities for automated pipelines alongside human developer identities in the same trust domain.

If you care about knowing not just what was signed but who actually signed it and whether that person had the right to — this talk is for you.
Keycloak + Sigstore: Binding Human Identity To Artifact Signatures - Oshi Gupta & Sagar UtekarA Decade of Cilium Around the World - Liz Rice, Isovalent at Cisco & Hiroki Hanada, Cybozu, Inc.Argo CD Maintainers Panel - Dan Garfield, Joanna Wyganowska, Michael Crenshaw & Nitish KumarVulnerability Response for Large Open Source Projects - Jo Guerreiro & Charline Voinot, Grafana LabsMeet Marcus Noble, CNCF AmbassadorSimon Forster: Why Non-Code Contributions Matter | KubeCon JapanRunning OpenSearch at Scale in High-Traffic Gaming Systems - Siddharth Vijay, Baazi GamesWhy CNCF Ambassador Sharma Shivlal Keeps Coming BackOpenTelemetry Celebrates Graduation and the Next Era of Agentic... - Alolita Sharma & Ted YoungProject Lightning Talk: Youki: Whats New and Whats Next? - Yuta Nagai, CyberAgent Inc.Turning Platform Engineering Work Into Business Value Leadership Understands - D. Cook & S. ForsterCNCFs Chris Aniszczyk on Bringing Kubernetes-Style Conformance to AI
CNCF [Cloud Native Computing Foundation] |

Keycloak + Sigstore: Binding Human Identity To Artifact Signatures - Oshi Gupta & Sagar Utekar

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER