MongoDB はデジタル署名を使用して、各 mongot パッケージが有効で未変更のリリースであることを証明します。mongot コンテナ イメージを検証して、正当性を確認します。
Community Edition
1
2
コンテナイメージを検証します。
{VERSION} を mongot バージョンタグに置き換えて、次のコマンドを実行します。
COSIGN_REPOSITORY=docker.io/mongodb/signatures \ cosign verify --private-infrastructure \ --key=./mongodb-search-community.pem \ "docker.io/mongodb/mongodb-community-search:{VERSION}"
成功した出力は次のようになります。
Verification for index.docker.io/mongodb/mongodb-community-search:{VERSION} -- The following checks were performed on each of these signatures: - The cosign claims were validated - The signatures were verified against the specified public key
Enterprise Edition
1
2
コンテナイメージを検証します。
{VERSION} を mongot バージョンタグに置き換えて、次のコマンドを実行します。
cosign verify \ --key mongodb-enterprise-kubernetes-operator.pem \ quay.io/mongodb/mongodb-search:{VERSION} \ --insecure-ignore-tlog
成功した出力は次のようになります。
WARNING: Skipping tlog verification is an insecure practice that lacks of transparency and auditability verification for the signature. Verification for quay.io/mongodb/mongodb-search:{VERSION} -- The following checks were performed on each of these signatures: - The cosign claims were validated - The signatures were verified against the specified public key