Docker高级应用与技巧深度解析
1. Docker镜像签名验证与内容信任
1.1 镜像签名验证
要验证Docker镜像是否已签名以及使用了哪个密钥,可以使用 docker trust inspect 命令。示例如下:
admin@myhome:~/$ docker trust inspect --pretty private-registry.mycompany.tld/registries/pythonapps/my-python-app:2.9BETA
执行该命令后,会输出镜像的签名信息,如下表所示:
| SIGNED TAG | DIGEST | SIGNERS |
| — | — | — |
| latest | 41c1003bfccce22a81a49062ddb088ea6478eabe - a1457430e6235828298593e6 | devops |
同时,还会显示签名者及其密钥列表,以及管理密钥信息:
List of signers and their keys for private-registry.mycompany.tld/registries/pythonapps/my-python-app:2.9BETA
SIGNER KEYS
devops 6b6b7688a444
Administrative keys for private-registry.mycompany
超级会员免费看
订阅专栏 解锁全文

被折叠的 条评论
为什么被折叠?



