cloudnative-pg / cloudnative-pg/postgres-containers
Cosign architecture-specific images too?
- Lenguaje dominante
- HCL
- Estrellas
- 154
- Forks
- 64
- Merge medio
- 4 d 12 h
- PR fusionados (30 d)
- 9
Descripción
If I `regctl image copy --referrers ghcr.io/cloudnative-pg/postgresql:18.4-standard-trixie private.goharbor.instance.com/cloudnative-pg/image:18.4`, the top level view appears like this with a green checkmark:
but if I click the "view this OCI index's artifact list" I get this:
so the architecture-specific images aren't signed. This means I can't enable the feature in Harbor that prevents downloads of non-cosigned images since the images from this repository aren't signed recursively.
Is there a reason only the top manifest is signed, or would it be possible to add `--recursive` to the `cosign sign` command that produces the release images in this organization?
Guía de contribución
Línea de trabajo
Busca la configuración de release que ejecuta el comando `cosign sign` para las imágenes de PostgreSQL e inspecciona cómo se gestionan los índices multiarquitectura. Verifica la lista de artefactos OCI resultante en Harbor, incluida cada imagen específica de una arquitectura, y confirma que el flujo de trabajo de release sigue completándose correctamente.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- docker, postgresql
- Área
- devops, release, security
- Tipo de issue
- Nueva funcionalidad
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Estado de actividad
- Tranquilo
- Claridad
- Bastante claro
- Aptitud para principiantes
- 48/100