Copy the supplied container image and signatures.
cosign copy [flags]
cosign copy <source image> <destination image>
# copy a container image and its signatures
cosign copy example.com/src:latest example.com/dest:latest
# copy the signatures only
cosign copy --sig-only example.com/src example.com/dest
# overwrite destination image and signatures
cosign copy -f example.com/src example.com/dest
# copy a container image and its signatures for a specific platform
cosign copy --platform=linux/amd64 example.com/src:latest example.com/dest:latest
--allow-http-registry whether to allow using HTTP protocol while connecting to registries. Don't use this for anything but testing
--allow-insecure-registry whether to allow insecure connections to registries (e.g., with expired or self-signed TLS certificates). Don't use this for anything but testing
--attachment-tag-prefix [AttachmentTagPrefix]sha256-[TargetImageDigest].[AttachmentName] optional custom prefix to use for attached image tags. Attachment images are tagged as: [AttachmentTagPrefix]sha256-[TargetImageDigest].[AttachmentName]
-f, --force overwrite destination image(s), if necessary
-h, --help help for copy
--k8s-keychain whether to use the kubernetes keychain instead of the default keychain (supports workload identity).
--platform string only copy container image and its signatures for a specific platform image
--sig-only only copy the image signature
--output-file string log output to a file
-t, --timeout duration timeout for commands (default 3m0s)
-d, --verbose log debug output
- cosign - A tool for Container Signing, Verification and Storage in an OCI registry.