Cosign Verification

This guide demonstrates how to verify signed artifacts (i.e., container images, Helm charts) hosted on ocir.immuta.com using Cosignarrow-up-right from Sigstorearrow-up-right.

circle-info

Cosign installation

To verify a signed artifact or blob, install Cosignarrow-up-right before proceeding.

Verify

  1. Create a file named immuta-cosign.pub with the following content:

    -----BEGIN PUBLIC KEY-----
    MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEIGUDdu5dgqxQTlbNt0bCIl+zCN65
    JC/PmmaC08Eb/UbpkSDmcn/t9Jh+w6Chwkkcp1olcOS1BqCaWrbtViu6Xg==
    -----END PUBLIC KEY-----
  2. Verify artifact signature.

    cosign verify \
        --key ./immuta-cosign.pub \
        ocir.immuta.com/stable/<artifact-name>:2024.2.20

Frequently asked question

How can I list all container images referenced in the IEHC?

circle-info

Yq installation

The following step presumes command-line tool yqarrow-up-right is installed.

List all container images by rendering the chart templates locally.

Last updated

Was this helpful?