GoogleCloudPlatform / GoogleCloudPlatform/cloud-sql-proxy

Sign released images with sigstore/cosign

オープン
#1,267 コメント 3 件 リアクション 4 件 担当者 1 名 @hessjcg に割り当て済み GitHub で見る
priority: p2 type: feature request
主要言語
Go
スター
1.4k
フォーク
352
平均マージ
14時間 54分
マージ済み PR(30日)
5

説明

## Feature Description
Start to sign the published OCI images using a documented identity.

It looks like you are using Google Cloud Build to publish your images, which @dlorenc added support for to get the `distroless` images signed, e.g.
https://github.com/GoogleContainerTools/distroless/blob/db2d69aa294c7ff414ae12c6ffe578254745a4ca/cloudbuild.yaml#L75

Currently, we inject these sidecars alongside a few of our images, and we'd love to be able to author policies stating that the images we pull down must be signed by your release process, e.g. `keyless@cloudsql-docker.iam.gserviceaccount.com`

## Alternatives Considered
N/A

## Additional Context

If you use Github actions for your releases this is even easier, and I could probably just send a PR, but either way an admin will have to do a bit of IAM setup to support this.

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。