{"repo":"containerd/imgcrypt","free":true,"listed":false,"github":"https://github.com/containerd/imgcrypt","clone":"git clone https://github.com/containerd/imgcrypt.git","description":"OCI Image Encryption Package","language":"Go","stars":435,"topics":["oci","oci-image","gpg","encryption","containers"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"imgcrypt image encryption library and command line tool Project imgcrypt is a non-core subproject of containerd. The imgcrypt library provides API extensions for containerd to support encrypted container images and implements the ctd-decoder command line tool for use by containerd to decrypt encrypted container images. An extended version of containerd's ctr tool ( ctr-enc ) with support for encrypting and decrypting container images is also provided. imgcrypt relies on the ocicrypt library for crypto functions on image layers. Usage imgcrypt requires containerd 1.3 or later. Containerd 1.4 or later is required when used with Kubernetes. For configuration instructions for kubernetes, please consult the CRI decryption document. Build and install imgcrypt : Start containerd with a configuration file that looks as follows. To avoid interference with a containerd from a Docker installation we use /tmp for directories. Also, we build containerd 1.3 from the source but do not install it. Create an RSA key pair using the openssl command line tool and encrypted an image: Start a local image registry so we can push the encrypted image to it. A recent versions of the registry is required to accept encrypted container images. Push the encrypted image to the local registry, pull it using ctr-enc , and then run the image. Project details imgcrypt is a non-core containerd sub-project, licensed under the Apache 2.0 license. As a containerd sub-project, you will find the: Project governance,","default_branch":null,"files":null,"tree":[],"storefront":"/r/containerd","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/containerd/imgcrypt/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}