cloudnative-pg / cloudnative-pg/postgres-containers
Cosign architecture-specific images too?
- 主要言語
- HCL
- スター
- 154
- フォーク
- 64
- 平均マージ
- 4日 12時間
- マージ済み PR(30日)
- 9
説明
If I `regctl image copy --referrers ghcr.io/cloudnative-pg/postgresql:18.4-standard-trixie private.goharbor.instance.com/cloudnative-pg/image:18.4`, the top level view appears like this with a green checkmark:
but if I click the "view this OCI index's artifact list" I get this:
so the architecture-specific images aren't signed. This means I can't enable the feature in Harbor that prevents downloads of non-cosigned images since the images from this repository aren't signed recursively.
Is there a reason only the top manifest is signed, or would it be possible to add `--recursive` to the `cosign sign` command that produces the release images in this organization?
コントリビューションガイド
調査の方向性
PostgreSQL イメージに対して `cosign sign` コマンドを実行するリリース設定を探し、マルチアーキテクチャインデックスがどのように処理されるかを確認します。Harbor で結果の OCI アーティファクト一覧を、各アーキテクチャ固有のイメージを含めて検証し、リリースワークフローが引き続き正常に完了することを確認します。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- docker, postgresql
- 領域
- devops, release, security
- issue の種類
- 機能追加
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 静か
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 48/100