Registry & Image Trust
You will learn where a signature stops a deploy: how an artifact is named, where its trust material is found, and what refuses to run it. Interviewers probe it because estates sign and never check.
on this pageshowhide
explore
- Distribution Integrity12 questions
- Undoing a Digest Pin4 questions
- Signature Discovery4 questions
- TUF Role Separation4 questions
- Refusing an Artifact13 questions
- Where Verification Runs5 questions
- Verification Implementations4 questions
- Enforcement Rollout4 questions
- What You Inherit7 questions
- Base Image Attack Surface4 questions
- Non-Container Artifacts3 questions
questions
page 2 of 2A shared build pins its base image by digest and nobody owns moving that pin — how do you resolve integrity versus freshness?
level: principalimportance: nice to knowfreq 38%
basics
~20 sPinning is an integrity control only: you get the exact bits you assessed, never a guarantee they are still good. It turns automatic updates into owned ones, so the pin is incomplete without a named owner and a visible age signal.
In a TUF-secured package index with thousands of maintainers, when is delegating targets authority worth its cost?
level: principalimportance: nice to knowfreq 28%
basics
~10 sDelegation is worth it when one top-level targets key would otherwise be able to sign for everybody. Per-namespace delegation scopes the blast radius, so compromising the index's own infrastructure cannot re-sign a maintainer's namespace.
showing 31–32 of 32