1
[Security] Is it time to sign the Docker images ??
Source: dani-garcia/vaultwarden#1783 · opened by @williamdes
Subject of the issue
Docker images when [signed]( are more "secure" in the case of a security event because a non signed image could not be pulled if the previous one was signed.
Deployment environment
Docker
Steps to reproduce
Expected behaviour
Have a signed image I can trust
Actual behaviour
No signed image
Troubleshooting data
All needed information can be found in official docs and in the GitHub action:
All the needed commands can be copied from
Is it easy to implement: Yes
Do you have to backup in a very safe place the repository and root keys, YES !!
Knowing nothing about DCT I implemented a GitHub action in a bunch of hours, I can provide help for the setup if needed
Docker images when [signed]( are more "secure" in the case of a security event because a non signed image could not be pulled if the previous one was signed.
Deployment environment
Docker
Steps to reproduce
Expected behaviour
Have a signed image I can trust
Actual behaviour
No signed image
Troubleshooting data
All needed information can be found in official docs and in the GitHub action:
All the needed commands can be copied from
Is it easy to implement: Yes
Do you have to backup in a very safe place the repository and root keys, YES !!
Knowing nothing about DCT I implemented a GitHub action in a bunch of hours, I can provide help for the setup if needed
No pledges yet. Be the first to back this.
Comments
Similar requests
Feature Request: Audit logging for successful personal vault logins
2 votes · 0 comments
Docker Secrets integration
3 votes · 0 comments
Reduce vulnerabilities of docker images
1 vote · 0 comments
Inline images in emails
4 votes · 0 comments
Publish container image to registry without draconian rate limits e.g. quay.io
1 vote · 0 comments
No comments yet.