skip to content

Registry & Image Trust

You will learn where a signature stops a deploy: how an artifact is named, where its trust material is found, and what refuses to run it. Interviewers probe it because estates sign and never check.

on this pageshow

explore

questions

page 2 of 2

A shared build pins its base image by digest and nobody owns moving that pin — how do you resolve integrity versus freshness?

level: principalimportance: nice to knowfreq 38%

basics

~20 s

Pinning is an integrity control only: you get the exact bits you assessed, never a guarantee they are still good. It turns automatic updates into owned ones, so the pin is incomplete without a named owner and a visible age signal.

open as a page

In a TUF-secured package index with thousands of maintainers, when is delegating targets authority worth its cost?

level: principalimportance: nice to knowfreq 28%

basics

~10 s

Delegation is worth it when one top-level targets key would otherwise be able to sign for everybody. Per-namespace delegation scopes the blast radius, so compromising the index's own infrastructure cannot re-sign a maintainer's namespace.

open as a page

showing 31–32 of 32