Sigstore Policy Controller
A Kubernetes admission controller that enforces signature and attestation policy on images before they are allowed to run.
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| Sigstore | verifies |
- Interfaces
container- Consumes
- oci-image, in-toto-attestation
- Runtime
- Needs network Deterministic Read-only Needs credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
- Website
- https://github.com/sigstore/policy-controller
- Repository
- https://github.com/sigstore/policy-controller
- License
- Apache-2.0 — read from the repository's LICENSE file, verified 2026-09-17
- Stars
- 180 · last commit 2026-09-14
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.