Test Image#
The test image is provided for testing and development purposes. It does not offer to run the NetHSM process with hardware-based separation (KVM), to encrypt the data store, or to use an external etcd. The connection between the NetHSM process and the integrated key-value store is unencrypted. The image is distributed as OCI image and can be run locally with a compatible executor such as Docker and Podman.
Võrreldes NetHSMi riistvaraga ei ole järgmised funktsioonid rakendatud tarkvarakonteineri REST API-s:
Network configuration
Factory reset
Reboot
Software update
The image can be obtained from Docker Hub.
Hoiatus
Do not use the test image under any circumstances for production data and use cases. For production environments with high security demands you must use the production image.
Tagging Policy#
The images in the repository are tagged with the Git commit hash from the main branch of the repository.
The latest image is tagged with testing
.
Konfiguratsioon#
The image can be configured with the following environment variables.
Environment variable |
Kirjeldus |
---|---|
|
Enables extended logging for NetHSM. |
Kasutamine#
Konteinerit saab täita järgmiselt.
$ docker run --rm -ti -p 8443:8443 docker.io/nitrokey/nethsm:testing
$ podman run --rm -ti -p 8443:8443 docker.io/nitrokey/nethsm:testing
This will run NetHSM as a Unix process inside the container and expose the REST API via the HTTPS protocol on port 8443.
Tähtis
Konteiner kasutab ise allkirjastatud TLS-sertifikaati. Veenduge, et ühenduse loomiseks kasutate õigeid ühendussätteid. Lisateavet leiate peatükist NetHSMi tutvustus.