Sign Your Container Images with Cosign, GitHub Actions and GitHub Container Registry (How To)

Описание к видео Sign Your Container Images with Cosign, GitHub Actions and GitHub Container Registry (How To)

Signing your container images is a great way to step up the container security game, and make sure your developers and users can trust the container images they receive.

And this is made much easier by GitHub Actions and GitHub Container Registry, which now are compatible with cosign.

In this video we will see how to sign a container image using cosign in GitHub Actions with the support of the GitHub Container Registry (GHCR)

🆘 NEED HELP? 🆘
Book a 1:1 Consultation with CoderDave: https://geni.us/cdconsult
We can talk about GitHub, Azure DevOps, or any other DevOps tool or project you need help with!

🙏🏻SUPPORT THE CHANNEL🙏🏻
Buy me a coffee: https://www.buymeacoffee.com/CoderDave
PayPal me donation: https://paypal.me/dabenveg

🎥VIDEOS
► Make Your Docker Build FASTER:    • 3 Steps to DRASTICALLY Improve Your D...  
► GitHub Container Registry Introduction:    • GitHub Container Registry: BETTER Tha...  
► SECURE Your Containers:    • 5 tools to SECURE your CONTAINER work...  

💬JOIN THE COMMUNITY
► Discord: https://geni.us/cddiscord
► Newsletter: https://coderdave.io/newsletter
► Blog: https://dev.to/n3wt0n
► GitHub: https://github.com/n3wt0n
► Twitter:   / davidebenvegnu  
► Facebook:   / coderdaveyt  

⏲TIMESTAMPS
0:00 Why you need to sign a container image
0:59 The tools: Sigstore, Cosign, GHCR
2:08 Let's generate the keys
3:40 Keys for GitHub
5:00 Giveaway winner announcement
5:25 Setup Cosign with GitHub Actions
7:37 Verify a container signature
8:31 Adding metadata to a container signature
9:53 Cosign GitHub starter workflow
11:19 Final Considerations

🎤PODCAST: https://geni.us/cdpodcast

❓QUESTIONS?
Have a question about DevOps, Cloud, Coding, or Anything Else? Post in comments section of this video!

🔴SUBSCRIBE to CoderDave here: https://www.youtube.com/CoderDave?sub...
_______________

👕Get my MERCH: https://geni.us/cdmerch

🔮TOOLS I USE
► Twingate - Connect to your Private Resources SECURELY: https://geni.us/twingate
► TubeBuddy - #1 YouTube channel Management tool (FREE): https://www.tubebuddy.com/CoderDave
► Moosend - Free Newsletter and Automation Platform: https://geni.us/moosend

📸🖥️GEAR AND SOFTWARE
► Music - Epidemic Sound (Get 30 days free): https://epidemicsound.com/referral/zf...
► Editing - Adobe Premiere Pro: https://geni.us/AdobeVideo
► Gear I Use for YouTube: https://kit.co/CoderDave/gear-i-use-f...
► Gear I Use for Streaming: https://kit.co/CoderDave/gear-i-use-f...
► My Computer Setup: https://kit.co/CoderDave/main-compute...
► Full office setup: https://github.com/n3wt0n/work-from-h...

Disclaimer:
Some product links are affiliate links which means if you buy something I'll receive a small commission at no additional cost to you.
As an Amazon Associate, I earn from qualifying purchases.

Комментарии

Информация по комментариям в разработке