cloudnative-pg / cloudnative-pg/postgres-containers

Cosign architecture-specific images too?

Open
#484 1 comment 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
HCL
Stars
154
Forks
64
Avg merge
4d 12h
Merged PRs (30d)
9

Description

If I `regctl image copy --referrers ghcr.io/cloudnative-pg/postgresql:18.4-standard-trixie private.goharbor.instance.com/cloudnative-pg/image:18.4`, the top level view appears like this with a green checkmark:
Image
but if I click the "view this OCI index's artifact list" I get this:
Image
so the architecture-specific images aren't signed. This means I can't enable the feature in Harbor that prevents downloads of non-cosigned images since the images from this repository aren't signed recursively.

Is there a reason only the top manifest is signed, or would it be possible to add `--recursive` to the `cosign sign` command that produces the release images in this organization?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.