Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Signing and Verifying Multi-architecture Containers With Sigstore

OpenSSF via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Learn to sign and verify multi-architecture containers using Sigstore in this conference talk that demystifies container resolution and security practices. Explore the mechanics behind multi-architecture containers, understanding why `docker pull python:3` retrieves only one architecture and how to verify signed containers across different architectures. Discover the intricacies of OCI manifests, image layers, and tags, and their relationship to annotations including SBOMs, attestations, and signatures. Master strategies for generating and verifying container signatures with Cosign regardless of target architecture, while navigating real-world challenges in managing multi-arch images at scale. Gain insights into unexpected behaviors of registries and pull-through caches, and build foundational knowledge for implementing robust software supply chain security practices in containerized environments.

Syllabus

Signing and Verifying Multi-architecture Containers With Sigstore - Natalie Somersall, Chainguard

Taught by

OpenSSF

Reviews

Start your review of Signing and Verifying Multi-architecture Containers With Sigstore

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.