官术网_书友最值得收藏!

Ensuring the integrity of the image supply chain

Providing content trust of the image supply chain is one of the most important, but often neglected, topics in managing Docker images. In any distributed system that communicates and transfers data over an untrusted medium (such as the internet), it is crucial to provide a means of content trust a way of verifying both the source (publisher) and the integrity of data entering the system. For Docker, this is especially true for pushing and pulling images (data), which is performed by Docker Engine.

The Docker ecosystem describes the concept of Docker Content Trust (DCT), which provides a means of verifying the digital signatures of data being transferred between the Docker Engine and the Docker Registry. This verification allows the publishers to sign their images and the consumer (Docker Engine) to verify the signatures to ensure the integrity and source of the images.

In the Docker CLI, it is possible to sign an image using the docker trust command, which is built on top of Docker Notary. This is a tool that's used for publishing and managing trusted collections of content. Signing images requires a Docker Registry with an associated Notary server, for example, Docker Hub.

To learn more about content trust for a private Azure Container Registry, please refer to  https://docs.microsoft.com/en-us/azure/container-registry/container-registry-content-trust.
主站蜘蛛池模板: 东乌| 土默特右旗| 图木舒克市| 玉林市| 南郑县| 吕梁市| 巨野县| 郓城县| 花莲市| 沙坪坝区| 当雄县| 华安县| 徐汇区| 兰西县| 武邑县| 汶川县| 彭泽县| 呼伦贝尔市| 铜梁县| 高尔夫| 兴化市| 菏泽市| 旺苍县| 黔东| 临猗县| 连平县| 祁门县| 长沙县| 华宁县| 五台县| 苗栗市| 汽车| 香港| 渑池县| 铜梁县| 开封县| 仙居县| 龙里县| 石渠县| 遂平县| 安福县|