Verifying a container image during deployment
If you use Amazon Signer and want to verify signed container images at the time of deployment, you can use one of the following solutions:
-
Gatekeeper and Ratify
– Use Gatekeeper as the admission controller and Ratify configured with an Amazon Signer plugin as a web hook for validating signatures. -
Kyverno
– A Kubernetes policy engine configured with an Amazon Signer plugin for validating signatures.
Note
Before verifying container image signatures, configure the Notation