Project Lightning Talk: Notary Project: Securing Binary Artifacts with Fine-grained Control - Yi Zha

Yi Zha

KubeCon + CloudNativeCon Europe 2025 · Project Lightning Talk

Overview

In an era marked by escalating cyberattacks targeting the software supply chain, ensuring the authenticity and integrity of digital artifacts has become paramount. This talk, delivered by Yi Zha, a maintainer of the Notary Project, provides an overview of the project's foundational capabilities and introduces a significant new feature: the ability to sign arbitrary blob files. The Notary Project offers a standard-based solution designed to help developers and organizations ascertain that the artifacts they consume originate from trusted sources and have not been tampered with since their creation.

Watch on YouTube

Key moments

  1. 0:00 Introduction to Notary Project and supply chain security
  2. 1:18 Notary Project overview, OCI compliance, and standards
  3. 2:15 Typical use case: Securing OCI images throughout lifecycle
  4. 4:00 New feature: Expanding signing to arbitrary blob files
  5. 4:48 How to use new blob signing feature with notation commands
  6. 5:49 Learn more: Join maintenance track or visit project kiosk

Project Lightning Talk: Notary Project: Securing Binary Artifacts with Fine-grained Control - Yi Zha

Speakers: Yi Zha, Notary Project Maintainer

Conference: KubeCon EU

YouTube: https://www.youtube.com/watch?v=dT-ShZYM3SI

Overview

In an era marked by escalating cyberattacks targeting the software supply chain, ensuring the authenticity and integrity of digital artifacts has become paramount. This talk, delivered by Yi Zha, a maintainer of the Notary Project, provides an overview of the project's foundational capabilities and introduces a significant new feature: the ability to sign arbitrary blob files. The Notary Project offers a standard-based solution designed to help developers and organizations ascertain that the artifacts they consume originate from trusted sources and have not been tampered with since their creation.

The core challenge addressed by the Notary Project revolves around fostering trust in a complex, multi-vendor software ecosystem. By adhering to open standards such as OCI 1.1, JWS, and COSE, the project aims to provide interoperable tools and specifications that allow for efficient management and verification of digital signatures. This presentation highlights how the Notary Project, already adopted by major cloud vendors and open-source initiatives, is expanding its reach beyond traditional container images to secure a broader spectrum of cloud-native artifacts, thereby fortifying the entire software supply chain against malicious alterations and unauthorized distribution.

The talk underscores the critical importance of extending signing capabilities to non-OCI artifacts, acknowledging that many vital components within a cloud-native environment exist as generic blob files. The introduction of new commands within the notation tool specifically for signing, inspecting, and verifying these arbitrary files represents a crucial step towards comprehensive supply chain security. This enhancement empowers organizations with fine-grained control over the trust policies governing their software assets, enabling a more robust defense against increasingly sophisticated supply chain attacks.

Background

▶ Watch: Introduction to Notary Project and supply chain security (0:00)

The pervasive threat of cyberattacks against the software supply chain has brought the issue of artifact authenticity and integrity to the forefront of cybersecurity concerns. Developers and organizations constantly grapple with fundamental questions: "How can I ensure artifacts that I use are from trusted sources?" and "How can I ensure those artifacts are not altered since creation?" These questions underpin the necessity for robust signing and verification mechanisms across the entire software development and deployment lifecycle.

The Notary Project emerged as a response to these challenges, providing a suite of standard-based solutions and tools. It aligns with the OCI artifact specification (version 1.1), which enables efficient management of signatures within OCI-compliant registries. This adherence to OCI standards ensures broad compatibility and interoperability within the cloud-native ecosystem. Furthermore, the project supports two IETF standard-based signature formats: JSON Web Signature (JWS) for human-readable signatures and CBOR Object Signing and Encryption (COSE) for binary-encoded, compact signatures, offering flexibility based on specific use cases and performance requirements. The Notary Project also publishes additional specifications, empowering developers to build custom reference implementations tailored to their unique needs, particularly beneficial in diverse multi-cloud environments where interoperability is key. Its widespread adoption by major cloud vendors and popular open-source projects underscores its growing significance in the industry.

A typical scenario for Notary Project's application involves ensuring the authenticity and integrity of OCI images throughout their lifecycle. For instance, when acquiring images from public repositories like Docker Hub, organizations can use Notary Project to verify the signatures, confirming they originate from a trusted source. Once acquired, these images might be moved to an internal catalog registry for further processing. This often involves vulnerability scanning and the generation of vulnerability reports. In some cases, organizations might even patch these images before upstream updates are available. For these modified images or newly generated reports, Notary Project can be used to sign them, establishing a chain of trust. During the build phase, before using base images for application development, verifying their signatures ensures they are trusted and approved for use within the organization. After creating custom application images, associated artifacts such as attestations, Software Bill of Materials (SBOM) files, and vulnerability reports can also be signed using Notary Project. Finally, before deploying container images into production, policy controllers can leverage Notary Project signatures to validate that only trusted and unaltered images are allowed to run, thus enforcing organizational security policies at the final deployment gate. This comprehensive approach establishes a secure perimeter around the entire software supply chain, from initial acquisition to final deployment.

Key Findings

▶ Watch: Typical use case: Securing OCI images throughout lifecycle (2:15)

The central and most significant finding presented in this talk is the expansion of the Notary Project's signing capabilities to encompass arbitrary blob files. While the Notary Project has historically focused on securing OCI images and related artifacts distributed via OCI registries, this new feature addresses a critical gap in the broader cloud-native software supply chain. Many essential artifacts, such as configuration files, scripts, manifests, custom binaries, or other data payloads, are not yet distributed as formal OCI artifacts but are equally vital to the integrity and authenticity of an application or system.

The project recognizes that these "arbitrary blobs" carry the same, if not greater, security implications as container images. Tampering with a critical configuration file or a deployment script can have devastating consequences, potentially leading to system compromise or data breaches. By extending its robust signing and verification mechanisms to these generic files, Notary Project provides a more holistic and comprehensive approach to supply chain security.

To facilitate this new capability, the Notary Project has introduced several new commands within its primary command-line interface tool, notation:

  • notation blob sign: This command enables users to digitally sign any arbitrary file, producing a signature that can then be published alongside the artifact.
  • notation blob inspect: This command allows for the inspection of signatures associated with arbitrary files, providing details about the signature, the signer's certificate, and other relevant metadata.
  • notation blob policy: This command is used to initialize and manage trust policies specifically for arbitrary blob files. These policies define which signatures and signers are considered trustworthy by a consumer, enabling fine-grained control over accepted artifacts.
  • notation blob verify: This command is employed by consumers to validate the digital signature of an arbitrary blob file against established trust policies, ensuring its authenticity and integrity before use.

These new tools signify a pivotal shift, moving the Notary Project beyond container image-centric security to a more expansive vision that can secure virtually any digital artifact within the cloud-native ecosystem. This enhancement empowers organizations to establish and enforce a consistent security posture across all components of their software supply chain, regardless of their packaging or distribution format.

Technical Deep Dive

▶ Watch: New feature: Expanding signing to arbitrary blob files (4:00)

The Notary Project's technical foundation is built upon open standards to ensure maximum interoperability and flexibility. At its core, it leverages the OCI artifact specification 1.1, which dictates how artifacts and their associated metadata, including signatures, are stored and managed within OCI-compliant registries. This allows Notary Project signatures to be treated as first-class artifacts within the existing registry infrastructure, making signature management efficient and scalable. Signatures themselves are generated using either JSON Web Signature (JWS) or CBOR Object Signing and Encryption (COSE). JWS provides a JSON-based structure for signing, suitable for scenarios requiring human readability and broader web integration, while COSE offers a compact binary format, ideal for resource-constrained environments or high-performance applications. Both standards are robust, cryptographically secure, and widely adopted.

The existing workflow for OCI images exemplifies the project's design philosophy. When an organization acquires a container image, perhaps from a public repository, the initial step involves using Notary Project tools to verify the image's signature. This verification process confirms that the image originates from a trusted publisher and has not been altered since it was signed. Once verified, the image might enter an internal lifecycle, including vulnerability scanning, where tools generate reports detailing any discovered vulnerabilities. In some advanced scenarios, development teams might even patch these images to address critical vulnerabilities before an official upstream fix is available. For these newly generated vulnerability reports, patched images, or even Software Bill of Materials (SBOM) files that detail the components within an image, the Notary Project can be used to sign them. This creates a verifiable audit trail and establishes internal trust for these derived artifacts.

Further along the development pipeline, when developers use base images to build their own custom applications, Notary Project's verification capabilities are crucial. By integrating signature verification into the Continuous Integration (CI) process, organizations can ensure that only trusted and approved base images are used, preventing the introduction of supply chain risks early in the development cycle. Once a custom application image is built, additional metadata such as attestations, runtime configuration files, or further vulnerability reports can be generated and, importantly, signed. Finally, before deployment to production environments, policy controllers (e.g., admission controllers in Kubernetes) can enforce policies that mandate Notary Project signature validation. This ensures that only images with valid, trusted signatures are allowed to be deployed, serving as a critical last line of defense against compromised or unauthorized artifacts.

The significant expansion introduced in this talk is the ability to sign arbitrary blob files. This addresses artifacts that are not yet packaged as OCI images but are equally critical to the security posture. Examples could include:

  • Kubernetes YAML manifests
  • Terraform configuration files
  • Custom shell scripts or binaries
  • Policy-as-code definitions
  • Machine learning models
  • Sensitive data files

The process for arbitrary blob signing mirrors the established principles for OCI images. Before these artifacts "leave your trust boundary," such as a developer's local file system or a secure build environment, they are signed using the new notation blob sign command. This produces a digital signature that is cryptographically bound to the artifact. This signature, along with the original arbitrary file, can then be published or distributed. From a consumer's perspective, before utilizing the arbitrary file, they would employ notation blob verify. This command checks the integrity of the file against its signature and validates the signature against a predefined trust policy.

The trust policy is a cornerstone of Notary Project's fine-grained control. It's a configuration that defines what signatures and signers are acceptable. For instance, an organization might configure a trust policy to only accept artifacts signed by specific organizational keys, or keys issued by a particular Certificate Authority (CA). This allows administrators to tightly control the provenance of all artifacts, significantly reducing the attack surface. The notation blob policy command enables the initialization and management of these policies, allowing organizations to tailor their security requirements precisely. The notation blob inspect command provides transparency, allowing users to examine the signature details, including the certificate information of the signer, without necessarily verifying against a policy. This comprehensive set of tools within notation provides a robust, standard-based framework for securing a vastly expanded range of digital assets within the software supply chain.

Demo / Proof of Concept

▶ Watch: How to use new blob signing feature with notation commands (4:48)

The specific talk at KubeCon EU, "Project Lightning Talk: Notary Project: Securing Binary Artifacts with Fine-grained Control - Yi Zha," did not include a live demonstration or a detailed proof of concept during the presentation itself. The speaker, Yi Zha, instead directed attendees interested in seeing a demo to join the Notary Project's maintenance track session on the last day of the conference or visit the project's kiosk. Therefore, this particular lightning talk focused on the conceptual overview and the announcement of the new arbitrary blob signing feature rather than a practical demonstration.

Defensive Implications

▶ Watch: Learn more: Join maintenance track or visit project kiosk (5:49)

The expansion of the Notary Project to include arbitrary blob file signing has profound defensive implications for organizations grappling with software supply chain security. This capability empowers defenders to implement a more comprehensive and granular security posture across their entire digital estate.

Firstly, organizations can now enforce signing policies for virtually all critical artifacts, not just container images. This means configuration files, Kubernetes manifests, deployment scripts, custom binaries, and even sensitive data files can be digitally signed at their point of origin. This significantly broadens the scope of secured assets, closing potential attack vectors that might otherwise be overlooked. Defenders should identify all critical non-OCI artifacts within their development and deployment pipelines and establish mandatory signing requirements for them.

Secondly, the ability to verify signatures at multiple stages—from artifact acquisition and internal processing to build-time and final deployment—provides layers of defense. Integrating notation blob verify into CI/CD pipelines ensures that any arbitrary file used or produced is validated against a trusted signature. This proactive verification helps detect tampering or unauthorized modifications early, preventing compromised artifacts from propagating through the system. For example, before applying a Kubernetes manifest, its signature can be verified to ensure it hasn't been maliciously altered.

Thirdly, the introduction of fine-grained trust policies through notation blob policy is a powerful defensive tool. Organizations can define exactly which signing identities (e.g., specific developer teams, automated build systems, or external vendors) are authorized to sign particular types of artifacts. This minimizes the risk of accepting artifacts from untrusted or unknown sources. Defenders can craft policies that align with their organizational structure and security requirements, enabling precise control over the provenance of all digital assets.

Furthermore, by integrating Notary Project tools into their existing security and operational workflows, organizations can achieve improved traceability and auditability. Every signed artifact carries verifiable proof of its origin and integrity, which is invaluable for incident response, compliance audits, and forensic analysis. If a breach occurs, the ability to quickly determine if an artifact has been tampered with and by whom (or from which source) significantly aids in containment and remediation efforts.

In essence, the Notary Project's enhanced capabilities allow defenders to reduce the risk of using tampered or unauthorized artifacts across a much wider array of components. By establishing a robust, standards-based framework for signing and verifying arbitrary blob files, organizations can build a more resilient and trustworthy software supply chain, effectively mitigating a significant class of modern cyber threats.

Key Takeaways

  • Comprehensive Supply Chain Security: The Notary Project provides standard-based solutions to ensure the authenticity and integrity of software artifacts, crucial for combating rising software supply chain attacks.
  • Arbitrary Blob File Signing: A major new feature extends Notary Project's capabilities to sign virtually any digital artifact (e.g., configuration files, scripts, manifests) beyond traditional OCI container images, addressing a critical gap in cloud-native security.
  • Standards-Based Foundation: The project adheres to OCI artifact specification 1.1 and supports IETF standard signature formats, JWS and COSE, ensuring interoperability and robust cryptographic security.
  • notation Tool Enhancements: The notation CLI tool now includes new blob subcommands (sign, inspect, policy, verify) to facilitate the signing and verification of arbitrary files, offering fine-grained control.
  • Fine-Grained Trust Policies: Organizations can define and enforce precise trust policies to specify which signatures and signers are acceptable, enhancing control over artifact provenance and reducing risks from untrusted sources.
  • Multi-Stage Verification: Notary Project enables verification of artifact signatures at various stages of the software lifecycle, from acquisition and internal processing to build-time and deployment, providing layered defense against tampering.

About the Speaker(s)

Yi Zha is a dedicated maintainer of the Notary Project. In this role, Yi is at the forefront of developing and advancing the project's capabilities, particularly in securing software supply chains. The presentation reflects deep expertise in the challenges of artifact integrity and authenticity in modern cloud-native environments and a commitment to providing standard-based, interoperable solutions.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This talk from a Notary Project maintainer outlines a crucial new capability: signing arbitrary blob files. This expands the project's utility beyond OCI images, addressing a significant blind spot in software supply chain security. The discussion of standards, workflow, and fine-grained trust policies provides valuable context and actionable insights for defenders. While a live demo would have elevated the presentation, the technical content is robust and highly impactful.

Heather Calloway (CISO) — STRONG ACCEPT

This talk introduces a critical evolution in the Notary Project, extending its robust signing and verification capabilities to arbitrary blob files beyond traditional OCI images. This is not a mere technical enhancement; it's a direct response to a significant institutional risk in the software supply chain, providing a standards-based framework to establish clear ownership and accountability for the integrity of critical configuration, script, and manifest files. The ability to define fine-grained trust policies and integrate verification into the CI/CD pipeline offers a tangible path for organizations to operationalize trust and significantly reduce their exposure to supply chain attacks.

→ Top-rated talks at KubeCon + CloudNativeCon Europe 2025

All talks from KubeCon + CloudNativeCon Europe 2025