/ / /
O MongoDB usa assinaturas digitais para certificar que cada pacote mongot é uma versão válida e inalterada. Verifique a imagem do contêiner mongot para confirmar sua autenticidade.
Community Edition
1
2
Verificar a imagem do contêiner.
Substitua {VERSION} pela tag de versão mongot e execute o seguinte comando:
COSIGN_REPOSITORY=docker.io/mongodb/signatures \ cosign verify --private-infrastructure \ --key=./mongodb-search-community.pem \ "docker.io/mongodb/mongodb-community-search:{VERSION}"
A saída bem-sucedida é semelhante à seguinte:
Verification for index.docker.io/mongodb/mongodb-community-search:{VERSION} -- The following checks were performed on each of these signatures: - The cosign claims were validated - The signatures were verified against the specified public key
Enterprise Edition
1
2
Verificar a imagem do contêiner.
Substitua {VERSION} pela tag de versão mongot e execute o seguinte comando:
cosign verify \ --key mongodb-enterprise-kubernetes-operator.pem \ quay.io/mongodb/mongodb-search:{VERSION} \ --insecure-ignore-tlog
A saída bem-sucedida é semelhante à seguinte:
WARNING: Skipping tlog verification is an insecure practice that lacks of transparency and auditability verification for the signature. Verification for quay.io/mongodb/mongodb-search:{VERSION} -- The following checks were performed on each of these signatures: - The cosign claims were validated - The signatures were verified against the specified public key