0PricingLogin
Helm Academy · Lesson

Verifying with helm verify and --verify

Rejecting charts that fail the signature check.

Checking the Signature

Signing is only half the story. The consumer's job is to verify that the chart and its .prov agree before trusting it.

The verify Command

Run helm verify against a downloaded .tgz that already has its .prov beside it. Helm checks both the hash and the signature.

helm verify mychart-0.1.0.tgz

All lessons in this course

  1. What a Provenance File Guarantees
  2. Signing a Chart with helm package --sign
  3. Verifying with helm verify and --verify
  4. Keyless Signing with Sigstore Cosign
← Back to Helm Academy