AWS 406: Artifact encryption, signing, integrity, retention, and provenance
Why this lesson matters
An artifact is the exact output promoted to runtime: package, image, template, Lambda archive, model or configuration bundle. Encryption protects confidentiality, a digest detects byte changes, a signature binds an authorized signer to content, provenance records how it was produced, and retention preserves evidence. None substitutes for the others.
Identity from source to runtime
Build once from an immutable source revision and promote the same bytes. Assign a cryptographic digest immediately; names such as latest, version labels and S3 keys are references, not content identity. A release manifest binds source commit, build definition and runner image digests, dependency lock/SBOM, artifact digest, test/scanner results, signing profile/version, timestamp, target environments and approvals.
Provenance is trustworthy only when the producing identity, build isolation and metadata are trustworthy. A self-authored statement from a compromised build is not independent evidence. Protect the control plane that changes workflows, dependencies, signer policy and verification policy. Record exceptions as signed, expiring policy decisions rather than editing evidence.
| Control | Proves/protects | Does not prove |
|---|---|---|
| SHA-256 digest | Exact bytes have not changed | Who built them or whether safe |
| SSE-KMS | Confidentiality and controlled key use | Source quality or immutability |
| Signature | Authorized signing identity approved bytes | Vulnerability-free behavior |
| Provenance | Claimed source/build inputs and process | Truth if builder is compromised |
| SBOM | Declared components/dependencies | Complete exploitability analysis |
| Object Lock | Retained protected object version | Correctness or availability of KMS key |
Storage, encryption and immutability
For S3, enable versioning, block public access, TLS-only bucket policy and default SSE-KMS when customer-managed key control is required. Separate build write from deploy read. Key policy and grants must permit only intended producer/consumer roles and encryption context; S3 permission alone cannot decrypt. Replication requires explicit destination/KMS design and monitoring.
S3 Version IDs preserve generations, but a principal with delete/version permission can still remove them. S3 Object Lock requires a versioned bucket. Governance mode can be bypassed only by specially authorized principals; compliance mode prevents protected-version deletion, including by root, until retention expires. Legal holds are separate. Choose retention before use because immutable mistakes consume storage and cannot be casually undone.
For ECR, use immutable tags where appropriate, but deploy by image digest. Configure encryption at repository creation, scan images under a defined policy, restrict pull/push/delete and use lifecycle policy only for artifacts outside required retention. Copying between stores must preserve and verify identity, metadata and signatures.
Signing and verification
AWS Signer uses a signing profile to produce signatures for supported artifact types and integrates with service-specific verification paths. Signing proves possession/use of an authorized signing identity under a profile, not that code is safe. Protect profile permissions, cancellation/revocation operations and key control separately from build roles.
Verification is an admission gate. Resolve the immutable digest, recompute/compare integrity, validate signature chain/profile and revocation status, verify provenance subject digest and builder/workflow identity, enforce source/branch/environment policy, check required tests/scans and record the result. Fail closed for production when evidence is absent, malformed, expired or tied to another digest. Define emergency override approvers, duration, scope and retrospective test.
sha256sum release.tar.gz
aws s3api head-object --bucket ARTIFACT_BUCKET --key releases/app.tar.gz \
--version-id VERSION_ID
aws s3api get-object-retention --bucket ARTIFACT_BUCKET --key releases/app.tar.gz \
--version-id VERSION_ID
aws signer list-signing-profiles
aws ecr describe-images --repository-name app --image-ids imageDigest=sha256:DIGEST
Do not confuse an S3 ETag with a universal SHA-256; multipart upload and encryption can change its meaning. Keep an explicit approved checksum/manifest and verify after upload, replication, restore and download. CloudTrail data events, KMS logs, signer records and deployment evidence establish who stored, signed, read and promoted each digest.
Lifecycle, recovery and workshop
Classify artifacts as candidate, approved, deployed, superseded, revoked, quarantined or expired. Retain every currently deployed digest plus rollback dependencies across the rollback horizon. A lifecycle rule must never delete the only recoverable version or its evidence. Test repository/Region recovery, key availability and verifier behavior offline. Revocation should block new deployment, locate affected environments and trigger a risk-based rollback or replacement; it does not remove running bytes automatically.
Build a manifest and SBOM linkage for three supplied artifacts. Detect a same-name/different-digest substitution, verify S3 version/retention and KMS policy evidence, evaluate a signature/provenance bundle, design an ECR/S3 promotion gate, then perform restore and revoked-artifact drills.
Test 22 failures: mutable tag, source rebuilt per environment, digest omitted, ETag treated as SHA-256, checksum not reverified, broad bucket writer, broad KMS decrypt, key disabled, replica cannot decrypt, version deletion allowed, lifecycle deletes rollback, Object Lock mode misunderstood, legal hold absent, signer role equals untrusted build, profile policy changed, signature for another digest, provenance self-asserted, SBOM detached, scan result stale, verifier fails open, revoked artifact still promoted, and emergency exception never expires.
Cost and acceptance
Price storage versions/retention/replication, KMS requests and keys, signing jobs, scanning, logs, retrieval/transfer and duplicate Regions. This lesson creates nothing. Submit threat model, immutable manifest, storage/KMS policies, retention matrix, signing/verification flow, promotion evidence, restore/revocation results and all diagnoses. Pass requires digest-based promotion, separated identities, fail-closed verification and tested recoverability.