krkn_lib.k8s.image_verification module

Pure-Python verification of Cosign-signed OCI images.

class krkn_lib.k8s.image_verification.CosignImageVerifier(public_key: str | bytes)

Bases: object

Verify key-based Cosign signatures without invoking external binaries.

__init__(public_key: str | bytes)
verify(image: str) → bool

Return whether image has a valid signature for this key.

exception krkn_lib.k8s.image_verification.ImageSignatureVerificationError

Bases: RuntimeError

Raised when an image required by a workload is not trusted.