STOP using Docker Image TAGS | Digests and Digital Signatures explained

Поділитися
Вставка
  • Опубліковано 28 лис 2024

КОМЕНТАРІ • 11

  • @MarcoLenzo
    @MarcoLenzo  Рік тому

    What do you use in your pipelines? Image names alone, tags, digests or digital signatures?

    • @MadanSemwal-fx4df
      @MadanSemwal-fx4df Рік тому

      😊😅😮❤😢😢❤😅😊

    • @MarcoLenzo
      @MarcoLenzo  Рік тому

      😅

    • @AaronJaeger
      @AaronJaeger 9 місяців тому +2

      Great explanations! Thank you for creating the video. I use digests for now. Looking at signatures.

    • @MarcoLenzo
      @MarcoLenzo  9 місяців тому +1

      @@AaronJaeger Thank you Aaron!
      When it comes to signatures, an element of friction I experienced at work is that not everyone was comfortable with using a public ledger (rekor) because certain info about private repositories was leaking there, e.g. repository URL.
      If there's the same concern in your team/organization, you'll have to manage a private rekor instance. Nothing impossible but it does complicate a bit more life.

  • @sergio0121
    @sergio0121 Рік тому +3

    Nice explanation

  • @anasouardini
    @anasouardini 10 місяців тому +1

    I think tags images should be readonly one published to the hub, unless you specify a different tag.

    • @MarcoLenzo
      @MarcoLenzo  10 місяців тому

      Incidentally today I was reading an article making the same point. 😄

  • @colunizator
    @colunizator 9 місяців тому +1

    Lol, why the dramatic background music :D

    • @MarcoLenzo
      @MarcoLenzo  9 місяців тому

      Lol 🤣 I stopped using background music ahahah but I guess I want to create some tension in this video!