Please enable GPG signing of charts for verification purposes
- Dominant language
- Mustache
- Stars
- 1.3k
- Forks
- 1.1k
- Avg merge
- 22m
- Merged PRs (30d)
- 5
Description
Helm supports signing charts to allow verification of the origin and validity of a chart package. This is done through the use of provenance files.
Could signing be added to the chart release process so we can consume the signature to verify the release? We have a requirement to cache the charts locally for use, and our security team would like us to be able to verify all releases before deployment.
Helm documentation: https://helm.sh/docs/topics/provenance/
Contributor guide
Research direction
Start with the chart release process and the linked Helm provenance documentation. Determine how released chart packages can receive provenance signatures and how consumers can verify them; done means published charts include verifiable signatures.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- helm
- Domain
- release, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100