Enhance Docker Image Security with Cosign
Budget: $10 – $65 USD
The primary goal of this project is to ramp up the security and trust levels during image deployment process. This will be achieved by implementing Cosign Key-based Image Signing and Attestation Workflow on Github Action using Hasicorp Vault.
Key responsibilities include:
- Setting up Cosign for Docker images to improve their security before deployment.
- Ensuring seamless interaction with existing CI/CD pipelines.
- Using Hasicorp Vault in the course of workflow setup on GitHub Action.
The successful candidate for this project will possess:
- Proficiency in GitHub Actions
- Extensive experience with Docker image management
- In-depth understanding of Hasicorp Vault
- Ability to integrate the new system with existing CI/CD pipelines
Note that your focus throughout should be on creating the highest security and trust in the Docker image deployment process. Understanding the intricacies of industry regulations and standards will be advantageous.
https://docs.sigstore.dev/key_management/overview/
Key responsibilities include:
- Setting up Cosign for Docker images to improve their security before deployment.
- Ensuring seamless interaction with existing CI/CD pipelines.
- Using Hasicorp Vault in the course of workflow setup on GitHub Action.
The successful candidate for this project will possess:
- Proficiency in GitHub Actions
- Extensive experience with Docker image management
- In-depth understanding of Hasicorp Vault
- Ability to integrate the new system with existing CI/CD pipelines
Note that your focus throughout should be on creating the highest security and trust in the Docker image deployment process. Understanding the intricacies of industry regulations and standards will be advantageous.
https://docs.sigstore.dev/key_management/overview/