8 days
oci repositories support signing artifacts, container trust policies are a thing. bootc repos are both signed and are distro repos, ostree Fedora and ublue are using it
Just because quay.io or hub.docker can be accessed without signatures or trust doesn’t mean there aren’t repos out there using it.


No, but if you wanted to do that, headscale is the answer