官术网_书友最值得收藏!

Ensuring the integrity of the image supply chain

Providing content trust of the image supply chain is one of the most important, but often neglected, topics in managing Docker images. In any distributed system that communicates and transfers data over an untrusted medium (such as the internet), it is crucial to provide a means of content trust a way of verifying both the source (publisher) and the integrity of data entering the system. For Docker, this is especially true for pushing and pulling images (data), which is performed by Docker Engine.

The Docker ecosystem describes the concept of Docker Content Trust (DCT), which provides a means of verifying the digital signatures of data being transferred between the Docker Engine and the Docker Registry. This verification allows the publishers to sign their images and the consumer (Docker Engine) to verify the signatures to ensure the integrity and source of the images.

In the Docker CLI, it is possible to sign an image using the docker trust command, which is built on top of Docker Notary. This is a tool that's used for publishing and managing trusted collections of content. Signing images requires a Docker Registry with an associated Notary server, for example, Docker Hub.

To learn more about content trust for a private Azure Container Registry, please refer to  https://docs.microsoft.com/en-us/azure/container-registry/container-registry-content-trust.
主站蜘蛛池模板: 偏关县| 阳江市| 巴东县| 那坡县| 工布江达县| 博客| 汉源县| 溧阳市| 巧家县| 佛山市| 万载县| 昂仁县| 白水县| 平顺县| 诸暨市| 虎林市| 宜兰县| 定日县| 平定县| 太白县| 蒲城县| 绥滨县| 林州市| 武夷山市| 巴林右旗| 错那县| 福贡县| 西青区| 台中县| 怀集县| 双桥区| 来凤县| 玉田县| 博乐市| 来凤县| 天长市| 澄城县| 镇安县| 辰溪县| 东乌珠穆沁旗| 雷山县|