官术网_书友最值得收藏!

Ensuring the integrity of the image supply chain

Providing content trust of the image supply chain is one of the most important, but often neglected, topics in managing Docker images. In any distributed system that communicates and transfers data over an untrusted medium (such as the internet), it is crucial to provide a means of content trust a way of verifying both the source (publisher) and the integrity of data entering the system. For Docker, this is especially true for pushing and pulling images (data), which is performed by Docker Engine.

The Docker ecosystem describes the concept of Docker Content Trust (DCT), which provides a means of verifying the digital signatures of data being transferred between the Docker Engine and the Docker Registry. This verification allows the publishers to sign their images and the consumer (Docker Engine) to verify the signatures to ensure the integrity and source of the images.

In the Docker CLI, it is possible to sign an image using the docker trust command, which is built on top of Docker Notary. This is a tool that's used for publishing and managing trusted collections of content. Signing images requires a Docker Registry with an associated Notary server, for example, Docker Hub.

To learn more about content trust for a private Azure Container Registry, please refer to  https://docs.microsoft.com/en-us/azure/container-registry/container-registry-content-trust.
主站蜘蛛池模板: 泰安市| 延吉市| 克东县| 长沙市| 洪湖市| 叶城县| 休宁县| 中方县| 梁河县| 彰化市| 苏尼特右旗| 正安县| 张北县| 高平市| 皋兰县| 利川市| 上虞市| 政和县| 平阴县| 铜陵市| 阿拉善左旗| 双辽市| 定日县| 汝城县| 奈曼旗| 兴文县| 景德镇市| 葫芦岛市| 澄江县| 汾西县| 克东县| 乃东县| 任丘市| 合山市| 台中市| 东乡县| 彝良县| 长阳| 顺昌县| 团风县| 甘孜|