We'd like to implement image signing for our imagestreams. We are unable to use 
`atomic cli` or skopeo to sign the images since we support other OS's and not 
just rpm based distros. 

There seems to be a way to write signatures using the registry API as written 


My question is about the signature.json payload. How is this file generated? Do 
we still need to sign the images first using `atomic cli` or skopeo? Is there a 
more generic way of signing the image streams?  


"version": 2,

"type": "atomic",


"content": "<cryptographic_signature>"


users mailing list

Reply via email to