skopeo/docs/skopeo-standalone-sign.1.md
Dave Hay ec73ff3d91 docs: Adding info re container signatures
Updating docs to reflect container signatures

Fixes #1337

Signed-off-by: Dave Hay <david_hay@uk.ibm.com>
2021-07-21 11:39:48 +02:00

1.4 KiB

% skopeo-standalone-sign(1)

NAME

skopeo-standalone-sign - Debugging tool - Publish and sign an image in one step.

SYNOPSIS

skopeo standalone-sign [options] manifest docker-reference key-fingerprint --output|-o signature

DESCRIPTION

This is primarily a debugging tool, useful for special cases, and usually should not be a part of your normal operational workflow; use skopeo copy --sign-by instead to publish and sign an image in one step.

manifest Path to a file containing the image manifest

docker-reference A docker reference to identify the image with

key-fingerprint Key identity to use for signing

--output|-o output file

EXAMPLES

$ skopeo standalone-sign busybox-manifest.json registry.example.com/example/busybox 1D8230F6CDB6A06716E414C1DB72F2188BB46CC8 --output busybox.signature
$

NOTES

This command is intended for use with local signatures e.g. OpenPGP ( other signature formats may be added in the future ), as per containers-signature(5). Furthermore, this command does not interact with the artifacts generated by Docker Content Trust (DCT). For more information, please see containers-signature(5).

SEE ALSO

skopeo(1), skopeo-copy(1), containers-signature(5)

AUTHORS

Antonio Murdaca runcom@redhat.com, Miloslav Trmac mitr@redhat.com, Jhon Honce jhonce@redhat.com