aws / aws/eks-charts

Please enable GPG signing of charts for verification purposes

Open
#1,034 0 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Mustache
Stars
1.3k
Forks
1.1k
Avg merge
22m
Merged PRs (30d)
5

Description

Helm supports signing charts to allow verification of the origin and validity of a chart package. This is done through the use of provenance files.

Could signing be added to the chart release process so we can consume the signature to verify the release? We have a requirement to cache the charts locally for use, and our security team would like us to be able to verify all releases before deployment.

Helm documentation: https://helm.sh/docs/topics/provenance/

Contributor guide

Open the contributing guide

Research direction

Start with the chart release process and the linked Helm provenance documentation. Determine how released chart packages can receive provenance signatures and how consumers can verify them; done means published charts include verifiable signatures.

Written by the indexing model from the issue text.

Assessment

Tech stack
helm
Domain
release, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.