Skip to content

Implement signed images verification #67

@konstantina-gramatova

Description

@konstantina-gramatova

All used container images must undergo a signature verification (if signed) based on the provided verification data. If the verification fails, running a container instance using such an image must be aborted with the appropriate error.

The verification has to be implemented integrating sigstore's Cosign.
If a global daemon's configuration is applicable, it has to be covered as well.

Metadata

Metadata

Labels

securitySecurity improvementtaskSingle unit of work

Type

No type

Projects

Status

Done

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions