Set of cross-industry specifications and tools for signing OCI artifacts and verifying signatures. Azure Container Registry uses it in place of Docker Content Trust.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Notary Project in context, with comparison tables and the common traps.
Terms in this definition
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- OCI
Standards body and specifications for container images and artefacts. Beyond images, Azure Container Registry can hold Helm charts, SBOMs and signatures in this format.
- Azure Container Registry
Private Azure registry for container images. Images can be geo-replicated, cleaned up by retention policies and built by ACR Tasks, while webhooks let a push kick off continuous deployment.
- Docker Content Trust
Signed-image push and pull on Premium ACR, based on Notary v1. It has been deprecated since 31 March 2025, can't be turned on for new registries after 31 May 2026, and goes away on 31 March 2028.
Related terms
- Notary v1
The signing approach underlying Docker Content Trust; Azure Container Registry has replaced it with Notary Project signing.
- Notation
Command-line tool from the Notary Project for signing container images and verifying their signatures, drawing on certificates held in Azure Key Vault via a plug-in.