{"id":619,"date":"2026-10-05T12:00:00","date_gmt":"2026-10-05T12:00:00","guid":{"rendered":"https:\/\/konteynerium.com\/index.php\/2026\/10\/05\/sbom-provenance-ve-cosign-ile-imaj-imzalama-tedarik-zinciri\/"},"modified":"2026-10-05T12:00:00","modified_gmt":"2026-10-05T12:00:00","slug":"sbom-provenance-ve-cosign-ile-imaj-imzalama-tedarik-zinciri","status":"publish","type":"post","link":"https:\/\/konteynerium.com\/index.php\/2026\/10\/05\/sbom-provenance-ve-cosign-ile-imaj-imzalama-tedarik-zinciri\/","title":{"rendered":"Tedarik Zinciri G\u00fcvenli\u011fi: SBOM, Provenance ve Cosign ile \u0130maj \u0130mzalama"},"content":{"rendered":"<p>Bir imaj\u0131 \u00e7al\u0131\u015ft\u0131rmadan \u00f6nce \u00fc\u00e7 soruya cevap verebilmelisiniz: <strong>\u0130\u00e7inde ne var?<\/strong> (SBOM) <strong>Nas\u0131l ve nerede \u00fcretildi?<\/strong> (provenance) <strong>Ger\u00e7ekten bizim \u00fcretti\u011fimiz imaj bu mu?<\/strong> (imza). Bunlar yaz\u0131l\u0131m tedarik zinciri g\u00fcvenli\u011finin \u00fc\u00e7 temel ta\u015f\u0131d\u0131r ve Docker&#8217;\u0131n modern ara\u00e7lar\u0131yla bug\u00fcn birka\u00e7 komutla elde edilebilir. Zafiyet taramas\u0131 (bkz. <a href=\"https:\/\/konteynerium.com\/index.php\/2026\/07\/03\/container-image-guvenligi-zafiyet-taramasi-en-iyi-uygulamalar\/\">Container Image G\u00fcvenli\u011fi<\/a>) &#8220;i\u00e7indeki paketlerde bilinen a\u00e7\u0131k var m\u0131?&#8221; sorusunu yan\u0131tlar; bu yaz\u0131 onun tamamlay\u0131c\u0131s\u0131d\u0131r.<\/p>\n<div class=\"callout\">\n  <span class=\"glyph\">i<\/span><\/p>\n<p><strong>Neyi test ettik, neyi etmedik?<\/strong> Provenance \u00fcretimini Docker 29.4 + Buildx 0.33 \u00fczerinde ger\u00e7ekten \u00e7al\u0131\u015ft\u0131rd\u0131k. SBOM \u00fcretimi ve <code>cosign<\/code> ad\u0131mlar\u0131n\u0131 bu ortamda deneyemedik (SBOM taray\u0131c\u0131 imaj\u0131 i\u00e7in Docker Hub eri\u015fimi, cosign i\u00e7in de a\u011f eri\u015fimi gerekiyor); bu b\u00f6l\u00fcmler resmi Docker ve Sigstore dok\u00fcmantasyonuna dayan\u0131r. Komutlar\u0131 kendi ortam\u0131n\u0131zda \u00f6nce deneme imaj\u0131nda \u00e7al\u0131\u015ft\u0131r\u0131n.<\/p>\n<\/div>\n<h2>1. SBOM: imaj\u0131n malzeme listesi<\/h2>\n<p>SBOM (Software Bill of Materials), bir imaj\u0131n i\u00e7indeki paketlerin, k\u00fct\u00fcphanelerin ve s\u00fcr\u00fcmlerin envanteridir. Yeni bir zafiyet a\u00e7\u0131kland\u0131\u011f\u0131nda (\u00f6rne\u011fin &#8220;\u015fu k\u00fct\u00fcphanenin 2.3 s\u00fcr\u00fcm\u00fcnde kritik a\u00e7\u0131k var&#8221;) imajlar\u0131n\u0131z\u0131 tek tek yeniden taramak yerine SBOM&#8217;lara bakarak etkilenen imajlar\u0131 hemen bulabilirsiniz.<\/p>\n<p>Buildx, SBOM&#8217;u build s\u0131ras\u0131nda \u00fcretip imaja <em>attestation<\/em> olarak ekleyebilir:<\/p>\n<pre><code>docker buildx build --sbom=true --tag kullanici\/uygulama:1.0 --push .\n\n# ya da push etmeden dosya olarak do\u011frulay\u0131n\ndocker buildx build --sbom=true --output type=local,dest=out .\n# out\/sbom.spdx.json dosyas\u0131 olu\u015fur<\/code><\/pre>\n<p>Dok\u00fcmantasyona g\u00f6re SBOM, SPDX standard\u0131nda JSON olarak \u00fcretilir. Registry&#8217;deki bir imaj\u0131n SBOM&#8217;unu g\u00f6rmek i\u00e7in:<\/p>\n<pre><code>docker buildx imagetools inspect kullanici\/uygulama:1.0 --format \"{{ json .SBOM }}\"<\/code><\/pre>\n<p>Varsay\u0131lan olarak yaln\u0131zca <strong>son a\u015fama<\/strong> taran\u0131r. Multi-stage build&#8217;de ara a\u015famalar\u0131n da (\u00f6rne\u011fin derleme ara\u00e7lar\u0131n\u0131n) listelenmesini istiyorsan\u0131z Dockerfile&#8217;a <code>ARG BUILDKIT_SBOM_SCAN_STAGE=true<\/code> ekleyebilirsiniz (bkz. <a href=\"https:\/\/konteynerium.com\/index.php\/2026\/10\/02\/multi-stage-build-ile-kucuk-imajlar\/\">Multi-Stage Build<\/a>).<\/p>\n<p>Denemeye \u00e7al\u0131\u015ft\u0131\u011f\u0131m\u0131zda BuildKit&#8217;in SBOM&#8217;u <code>docker\/buildkit-syft-scanner<\/code> adl\u0131 bir taray\u0131c\u0131 imaj\u0131 \u00e7ekerek \u00fcretti\u011fini g\u00f6rd\u00fck; yani build ortam\u0131n\u0131z\u0131n bu imaja (registry&#8217;ye) eri\u015febilmesi gerekir. Kapal\u0131 bir a\u011fda \u00e7al\u0131\u015f\u0131yorsan\u0131z taray\u0131c\u0131 imaj\u0131n\u0131 \u00f6nceden kendi registry&#8217;nize aynalaman\u0131z gerekir.<\/p>\n<h2>2. Provenance: imaj nas\u0131l \u00fcretildi?<\/h2>\n<p>Provenance, bir imaj\u0131n kim taraf\u0131ndan, hangi kaynaktan, hangi komutlarla \u00fcretildi\u011fini kaydeder (SLSA \u00e7er\u00e7evesiyle uyumlu). Mod se\u00e7ene\u011fi vard\u0131r: <code>mode=min<\/code> temel bilgiyi, <code>mode=max<\/code> build arg\u00fcmanlar\u0131, komutlar gibi ayr\u0131nt\u0131lar\u0131 da i\u00e7erir.<\/p>\n<pre><code>docker buildx build --provenance=mode=max --output type=local,dest=out .<\/code><\/pre>\n<p>Bu komutu \u00e7al\u0131\u015ft\u0131rd\u0131\u011f\u0131m\u0131zda \u00e7\u0131kt\u0131 dizininde <code>provenance.json<\/code> olu\u015ftu ve i\u00e7indeki <code>predicateType<\/code> alan\u0131 <code>https:\/\/slsa.dev\/provenance\/v1<\/code> idi; yani standart bir SLSA provenance belgesi. Bir imaj\u0131n <code>--provenance=mode=max<\/code> ile registry&#8217;ye g\u00f6nderilmi\u015f halini incelemek i\u00e7in:<\/p>\n<pre><code>docker buildx imagetools inspect kullanici\/uygulama:1.0 --format \"{{ json .Provenance }}\"<\/code><\/pre>\n<div class=\"callout\">\n  <span class=\"glyph\">!<\/span><\/p>\n<p><strong>\u00d6nemli \u00f6n ko\u015ful:<\/strong> Attestation&#8217;lar imaj indeksinin (image index) i\u00e7inde saklan\u0131r. Docker dok\u00fcmantasyonuna g\u00f6re klasik imaj deposu bu yap\u0131y\u0131 tutamaz; <code>docker<\/code> s\u00fcr\u00fcc\u00fcs\u00fcyle attestation i\u00e7in containerd imaj deposu gerekir. Docker 29.4 kurulumumuzda <code>docker info<\/code> \u00e7\u0131kt\u0131s\u0131nda <code>driver-type: io.containerd.snapshotter.v1<\/code> g\u00f6r\u00fcn\u00fcyordu; sizinki farkl\u0131ysa <code>docker-container<\/code> s\u00fcr\u00fcc\u00fcl\u00fc bir builder kullan\u0131n. Ayr\u0131ca varsay\u0131lan davran\u0131\u015f (hangi attestation&#8217;\u0131n otomatik eklendi\u011fi) s\u00fcr\u00fcme ve \u00e7\u0131kt\u0131 bi\u00e7imine g\u00f6re de\u011fi\u015febilir \u2014 beklentiye b\u0131rakmay\u0131p <code>--sbom<\/code> ve <code>--provenance<\/code> bayraklar\u0131n\u0131 a\u00e7\u0131k\u00e7a yaz\u0131n. Biz <code>type=oci<\/code> \u00e7\u0131kt\u0131s\u0131n\u0131 bayraks\u0131z ald\u0131\u011f\u0131m\u0131zda attestation eklenmedi\u011fini g\u00f6rd\u00fck.<\/p>\n<\/div>\n<h2>3. \u0130mzalama: bu imaj ger\u00e7ekten bizim mi?<\/h2>\n<p>SBOM ve provenance imaj\u0131n <em>ne oldu\u011funu<\/em> anlat\u0131r; imza ise <em>kim taraf\u0131ndan yay\u0131mland\u0131\u011f\u0131n\u0131 ve sonradan de\u011fi\u015ftirilmedi\u011fini<\/em> kan\u0131tlar. A\u00e7\u0131k kaynak d\u00fcnyas\u0131nda yayg\u0131n ara\u00e7 <strong>Sigstore&#8217;un cosign<\/strong>&#8216;\u0131d\u0131r. \u0130ki mod vard\u0131r: anahtar tabanl\u0131 ve anahtars\u0131z (keyless).<\/p>\n<pre><code># Anahtars\u0131z (OIDC ile; Google\/GitHub\/Microsoft hesab\u0131yla do\u011frular)\ncosign sign kullanici\/uygulama@sha256:ABC...\n\n# Anahtar \u00e7ifti ile\ncosign generate-key-pair\ncosign sign --key cosign.key kullanici\/uygulama@sha256:ABC...<\/code><\/pre>\n<p>\u0130mzay\u0131 etiket yerine <strong>digest<\/strong> ile atmak \u00f6nemlidir: etiket sonradan ba\u015fka bir imaj\u0131 i\u015faret edebilir (bkz. <a href=\"https:\/\/konteynerium.com\/index.php\/2026\/09\/29\/docker-imaji-ve-container-farki-katmanlar-etiketler-yasam-dongusu\/\">\u0130maj ve Container Fark\u0131<\/a>), digest ise i\u00e7eri\u011fe ba\u011fl\u0131d\u0131r. Do\u011frulama:<\/p>\n<pre><code># Anahtars\u0131z imza: kimin imzalad\u0131\u011f\u0131n\u0131 a\u00e7\u0131k\u00e7a belirtin\ncosign verify kullanici\/uygulama@sha256:ABC... \\\n  --certificate-identity=ben@ornek.com \\\n  --certificate-oidc-issuer=https:\/\/accounts.google.com\n\n# GitHub Actions ile imzaland\u0131ysa\ncosign verify kullanici\/uygulama@sha256:ABC... \\\n  --certificate-identity-regexp=https:\/\/github.com\/kurulu\u015f\/depo \\\n  --certificate-oidc-issuer=https:\/\/token.actions.githubusercontent.com\n\n# Anahtar \u00e7iftiyle\ncosign verify --key cosign.pub kullanici\/uygulama@sha256:ABC...<\/code><\/pre>\n<p>Do\u011frulamada <code>--certificate-identity<\/code> ve <code>--certificate-oidc-issuer<\/code> de\u011ferlerini <em>mutlaka<\/em> belirtin; bu olmadan &#8220;birisi imzalam\u0131\u015f&#8221; demenin g\u00fcvenlik de\u011feri \u00e7ok d\u00fc\u015f\u00fckt\u00fcr. \u00d6nemli olan, &#8220;herhangi bir imza&#8221; de\u011fil, &#8220;bekledi\u011fim kimli\u011fin imzas\u0131&#8221; olmas\u0131d\u0131r. cosign&#8217;\u0131n bayraklar\u0131 ve \u00e7\u0131kt\u0131 bi\u00e7imi s\u00fcr\u00fcmler aras\u0131nda de\u011fi\u015febildi\u011fi i\u00e7in kulland\u0131\u011f\u0131n\u0131z s\u00fcr\u00fcm\u00fcn <code>cosign sign --help<\/code> \u00e7\u0131kt\u0131s\u0131na bak\u0131n.<\/p>\n<h2>Hepsini bir arada: \u00f6rnek CI ak\u0131\u015f\u0131<\/h2>\n<ol>\n<li>\u0130maj\u0131 <code>--sbom=true --provenance=mode=max<\/code> ile build edip registry&#8217;ye g\u00f6nderin.<\/li>\n<li>Push sonras\u0131 digest&#8217;i al\u0131n.<\/li>\n<li><code>cosign sign<\/code> ile digest&#8217;i imzalay\u0131n (CI&#8217;da anahtars\u0131z imza i\u00e7in pipeline&#8217;a OIDC kimli\u011fi verilir).<\/li>\n<li>Da\u011f\u0131t\u0131m \u00f6ncesi (admission kontrol\u00fc ya da da\u011f\u0131t\u0131m beti\u011finde) <code>cosign verify<\/code> ile kimli\u011fi do\u011frulay\u0131n; do\u011frulanamayan imaj\u0131 \u00e7al\u0131\u015ft\u0131rmay\u0131n.<\/li>\n<\/ol>\n<p>CI\/CD taraf\u0131 i\u00e7in <a href=\"https:\/\/konteynerium.com\/index.php\/2026\/08\/14\/cicd-ile-docker-github-actions-otomatik-build-deploy\/\">CI\/CD ile Docker<\/a> yaz\u0131s\u0131na bak\u0131n; tarama ad\u0131m\u0131n\u0131 da pipeline&#8217;a eklemeyi unutmay\u0131n.<\/p>\n<h2>SBOM&#8217;u tarama ile birle\u015ftirmek<\/h2>\n<p>SBOM yaln\u0131zca envanter de\u011fil, s\u00fcrekli bir tarama girdisidir: SBOM&#8217;dan zafiyet taramas\u0131 yapan ara\u00e7lar vard\u0131r (Trivy ve Grype gibi), b\u00f6ylece imaj\u0131 yeniden \u00e7ekmeden &#8220;bug\u00fcn a\u00e7\u0131klanan zafiyetten hangi imajlar\u0131m\u0131z etkileniyor?&#8221; sorusunu yan\u0131tlars\u0131n\u0131z. Bu sitedeki <a href=\"https:\/\/konteynerium.com\/index.php\/container-guvenlik-sertlestirme-merkezi\/\">G\u00fcvenlik Merkezi<\/a>&#8216;nde Docker Bench ve Falco konular\u0131yla birlikte d\u00fc\u015f\u00fcn\u00fcn: SBOM &#8220;ne var&#8221;, tarama &#8220;a\u00e7\u0131k var m\u0131&#8221;, imza &#8220;do\u011fru imaj m\u0131&#8221;, Falco &#8220;\u00e7al\u0131\u015f\u0131rken ne yap\u0131yor&#8221; sorular\u0131n\u0131n cevab\u0131d\u0131r.<\/p>\n<h2>H\u0131zl\u0131 kontrol listesi<\/h2>\n<ul>\n<li>\u0130majlar\u0131n\u0131z <code>--sbom=true<\/code> ve <code>--provenance=mode=max<\/code> ile mi build ediliyor?<\/li>\n<li>Builder attestation destekliyor mu (containerd imaj deposu veya <code>docker-container<\/code> s\u00fcr\u00fcc\u00fcs\u00fc)?<\/li>\n<li>\u0130majlar\u0131 etiketle de\u011fil <strong>digest<\/strong> ile imzal\u0131yor ve do\u011fruluyor musunuz?<\/li>\n<li>Do\u011frulamada beklenen kimlik (<code>--certificate-identity<\/code>) ve sa\u011flay\u0131c\u0131 (<code>--certificate-oidc-issuer<\/code>) belirtiliyor mu?<\/li>\n<li>Da\u011f\u0131t\u0131m hatt\u0131n\u0131z imzas\u0131z imaj\u0131 reddediyor mu?<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>\u0130maj\u0131n\u0131z\u0131n i\u00e7inde ne var, nas\u0131l \u00fcretildi ve ger\u00e7ekten sizin mi? Buildx ile SBOM ve provenance \u00fcretimini, cosign ile digest imzalamay\u0131 ve kimlik do\u011frulamas\u0131yla verify etmeyi ad\u0131m ad\u0131m \u00f6\u011frenin.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"seviye":[9],"class_list":["post-619","post","type-post","status-publish","format-standard","hentry","category-orkestrasyon-guvenlik","seviye-ileri"],"_links":{"self":[{"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/posts\/619","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/comments?post=619"}],"version-history":[{"count":0,"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/posts\/619\/revisions"}],"wp:attachment":[{"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/media?parent=619"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/categories?post=619"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/tags?post=619"},{"taxonomy":"seviye","embeddable":true,"href":"https:\/\/konteynerium.com\/index.php\/wp-json\/wp\/v2\/seviye?post=619"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}