Skip to main content

Docker Images

Sign Docker images with cosign

Sign your Docker images after they're pushed.

Config

docker_signs:
  - artifacts: all
    cmd: cosign
    args: ["sign", "--key=cosign.key", "{{ Artifact }}@{{ Digest }}"]

Docker sign config fields

FieldTypeDefaultDescription
idstringUnique identifier for this docker sign config (referenced by ids filters elsewhere).
artifactsstring""Which Docker artifacts to sign: all, images, manifests, none, or "" (empty — the default — signs the canonical Docker images). The singular image / manifest are not accepted and hard-error at release time.
cmdstringcosignSigning command to invoke.
argslist["sign", "--key=cosign.key", "{{ .Artifact }}@{{ .Digest }}", "--yes"]Arguments passed to the signing command. {{ Artifact }} is replaced by the digest-pinned image reference and {{ Signature }} by the synthesized <image>@<digest>.sig name before the rest is rendered as a template; {{ Digest }} renders the image digest. The ${artifact} shell variables the binary/archive path expands are not expanded here and reach the signing command as literal text.
signaturestring—Ignored. A container signature is stored in the registry beside the image rather than written to a file, so anodizer synthesizes the <image>@<digest>.sig name its argv substitutes and reads this template nowhere. anodizer check config warns when it is set.
certificatestringCertificate file whose presence selects cosign's bundle verification mode. The path itself never reaches the signing command — {{ Certificate }} in args: renders empty.
idslistallOnly sign images from docker configs whose id is in this list.
stdinstringContent written to the signing command's stdin (e.g. a passphrase); rendered as a template (e.g. {{ Env.GPG_PASSPHRASE }}) with nothing substituted first, so neither {{ Artifact }} nor ${artifact} names anything here.
stdin_filestringPath to a file whose content is written to the signing command's stdin.
envlistEnvironment variables passed to the signing command (KEY=VALUE strings).
outputboolfalseCapture and log the signing command's stdout/stderr.
ifstringTemplate-conditional: skip this config when the rendered result is false or empty. An absent, empty or blank if: imposes no gate and always runs; the falsy test applies to what a non-blank gate renders.

Images are signed one at a time. A keyless config (no --key argument) also takes the same host-level advisory lock as keyless binary/archive signing, so two anodizer processes on one host queue on the sigstore TUF trust store instead of colliding on it.