notation icon indicating copy to clipboard operation
notation copied to clipboard

docs: add dm-verity image layer signing

Open dallasd1 opened this issue 1 month ago • 0 comments

This proposal discusses adding per-layer container image signing using the PKCS#7 format. This will enable signing individual container image layers that are later verified by the kernel at runtime.

Runtime verification also depends on milestone 1 of this RFC for code integrity in containerd. At the time of writing, milestone 1.2 is in PR review and milestone 1.3 remains.

dallasd1 avatar Dec 15 '25 16:12 dallasd1