Verify Portworx Docker image signatures with Cosign
This document explains how to ensure you are using a signed and verified Portworx container image for deploying container on your Kubernetes cluster. You can verify that a Portworx container image matches a trusted signature using Cosign. Cosign is part of the Sigstore project and is commonly used for container image signing and verification.
To verify Portworx image signature with Cosign, complete the following steps:
Prerequisites
Cosign is installed (v3.0.2 and above) on a machine that will access the image registry.
Download Portworx Cosign public key
-
Log in to Portworx Central and select Support.
-
In the Document and Other Guides section, locate Portworx Cosign Public Keys and click on Download Key.
-
Check the public key is downloaded and make a note of file path.