Daily challenges →
🔐 DevSecOps medium ⚡ 60 XP

What makes cosign "keyless" signing keyless?

In keyless mode you authenticate via OIDC (e.g., a CI job identity), Fulcio issues a minutes-long certificate binding that identity to an ephemeral key, and the signature is logged to Rekor — no key files to manage or leak.

🌊 This is a free sample — 1015+ more questions on DevOps Ocean

Sign in free to practice the full question bank with daily challenges, XP, streaks, duels and a global leaderboard.

Practice the full bank — free →