What changes
The legacy hosted trust service used by Docker Content Trust and Notary v1 stops supporting signing and verification workflows.
Who is affected
- Teams using
DOCKER_CONTENT_TRUSTworkflows backed by Notary v1. - CI/CD pipelines that sign or verify images through the legacy service.
- Policies and runbooks that assume the hosted Notary v1 trust server remains available.
Timeline
Docker schedules brownouts before the full shutdown on 8 December 2026. The brownouts are intended to expose remaining dependencies before permanent retirement.
Required action
- Inventory Content Trust and Notary v1 usage across build and deployment pipelines.
- Select a supported modern signing and verification approach.
- Migrate trust policy, keys and verification gates.
- Test deployments during the brownout period rather than waiting for final shutdown.
What is not affected
The retirement does not mean Docker images or registries generally stop working. It concerns the legacy trust service and associated workflows.
PlatformTrace analysis
This is a full service retirement with security-policy consequences: merely continuing to push and pull images does not preserve the old signature-verification control.
Sources
Corrections and updates
No correction is currently open. Brownout or shutdown-date changes will be recorded as dated updates.