-
Notifications
You must be signed in to change notification settings - Fork 53
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add cosign signing on build #816
Conversation
blocked by #817 as we need cosign and luet-cosign as deps |
Keyless signing test: https://github.com/Itxaka/test-oidc-signing/runs/4019264117?check_suite_focus=true pushed signature can be verified with Pretty straighforward |
Signed-off-by: Itxaka <[email protected]>
Ready for review @mudler After the test with github keyless and the manual test with keys, this should be good to go for the part of signing the images during build. NOTE: This currently pushes the signatures to the old dockerhub repo raccos/releases-flavor which we should create beforehand (old repos used the distro names, while we use the flavors). @mudler could you create the required repos ( |
@Itxaka Do we need each repo for each arch? |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Beautiful integration 💯
Signed-off-by: Itxaka [email protected]