workflow: sign release containers #1806
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Signs release containers with
cosign
. Also modified the publish workflow to support other registries. Makes it easier to test changes.Tests:
https://hub.docker.com/repository/docker/tkatila/intel-gpu-plugin/tags
Test runs:
https://github.com/tkatila/intel-device-plugins-for-kubernetes/actions/runs/10367001757/job/28697484565
https://github.com/tkatila/intel-device-plugins-for-kubernetes/actions/runs/10367083492/job/28697736086
cosign can be used to verify containers:
cosign verify --certificate-oidc-issuer https://token.actions.githubusercontent.com --certificate-identity-regexp https://github.com/tkatila/intel-device-plugins-for-kubernetes/.github/workflows/lib-publish.yaml.* tkatila/intel-gpu-plugin:0.30.101 | jq .