Sign inSign up

instructure/gpg-signer

By instructure

•Updated over 1 year ago

Sign files with a given GPG private key and passphrase.

Image
0

1.8K

instructure/gpg-signer repository overview

⁠gpg-signer

Signs arbitrary files in mounted volume with provided GPG key and passphrase, and stores the signature files in the same directory using the same uid:gid.

⁠Usage

Place any files you want signed in a dedicated directory, and mount that directory as volume /to-sign in the container. Provide your GPG private key via the environment variable GPG_PRIVATE_KEY, and the passphrase for using the key as GPG_PASSPHRASE. These are both highly sensitive values, so be sure to use appropriate secret management.

Example:

$ docker run --rm -it -v $(pwd)/my-signable-files:/to-sign \
      -e GPG_PRIVATE_KEY -e GPG_PASSPHRASE \
      instructure/gpg-signer

If there are no files provided, the script will exit immediately. Any errors importing the key or signing the provided files will immediately end the run.

Generated signature files will be named <original-filename>.asc.

Tag summary

Content type

Image

Digest

sha256:0d07f5abf…

Size

40.6 MB

Last updated

over 1 year ago

docker pull instructure/gpg-signer