AWS introduces container image signing
Share
Services
Today, [AWS Signer](https://docs.aws.amazon.com/signer/latest/developerguide/Welcome.html) and [Amazon Elastic Container Registry](https://aws.amazon.com/ecr/) (ECR) launched image signing, a new feature that enables you to sign and verify container images. You can now use Signer, a managed signing service, to validate that only container images you have approved are deployed in your Amazon Elastic Kubernetes Service (EKS) clusters.
You can use container image signing to help ensure the use of approved images inside your organization, which can help you meet your security and compliance requirements. You can sign and verify container images anytime during the development or deployment phases. You begin by creating a signing profile, a unique AWS Signer identity, to cryptographically sign images in your repository with client-side tools. Signer manages the signing keys, rotates code signing certificates, provides audit logs, and stores the signatures alongside your images. Amazon EKS and Kubernetes customers can choose their preferred admission controllers – like Gatekeeper or Kyverno, or develop their own tooling – to help enforce image verification before deploying images.
For more information about the AWS Regions where Signer is available, see the [AWS Region table](https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/). Signer is available at no additional cost. To learn more, read the [Signer](https://docs.aws.amazon.com/signer/latest/developerguide/container-workflow.html) and [ECR](https://docs.aws.amazon.com/AmazonECR/latest/userguide/what-is-ecr.html) documentation and [launch blog](https://aws.amazon.com/blogs/containers/announcing-container-image-signing-with-aws-signer-and-amazon-eks/).
What else is happening at Amazon Web Services?
Read update
Services
Share
Amazon Connect Contact Lens now provides real-time conversational analytics for chat
about 18 hours ago
Services
Share
Read update
Services
Share
AWS announces Amazon DynamoDB zero-ETL integration with Amazon Redshift
about 18 hours ago
Services
Share
AWS announces Amazon RDS for MySQL zero-ETL integration with Amazon Redshift (Public Preview)
about 18 hours ago
Services
Share
AWS announces Amazon Aurora PostgreSQL zero-ETL integration with Amazon Redshift (Public Preview)
about 18 hours ago
Services
Share