cloudnative-pg / cloudnative-pg/postgres-containers

Cosign architecture-specific images too?

オープン
#484 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
enhancement
主要言語
HCL
スター
154
フォーク
64
平均マージ
4日 12時間
マージ済み PR(30日)
9

説明

If I `regctl image copy --referrers ghcr.io/cloudnative-pg/postgresql:18.4-standard-trixie private.goharbor.instance.com/cloudnative-pg/image:18.4`, the top level view appears like this with a green checkmark:
Image
but if I click the "view this OCI index's artifact list" I get this:
Image
so the architecture-specific images aren't signed. This means I can't enable the feature in Harbor that prevents downloads of non-cosigned images since the images from this repository aren't signed recursively.

Is there a reason only the top manifest is signed, or would it be possible to add `--recursive` to the `cosign sign` command that produces the release images in this organization?

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

PostgreSQL イメージに対して `cosign sign` コマンドを実行するリリース設定を探し、マルチアーキテクチャインデックスがどのように処理されるかを確認します。Harbor で結果の OCI アーティファクト一覧を、各アーキテクチャ固有のイメージを含めて検証し、リリースワークフローが引き続き正常に完了することを確認します。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
docker, postgresql
領域
devops, release, security
issue の種類
機能追加
難易度
4/5
見積もり時間
3〜5日
活発さ
静か
明瞭さ
おおむね明確
初心者へのやさしさ
48/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。