cloudnative-pg / cloudnative-pg/postgres-containers

Cosign architecture-specific images too?

Đang mở
#484 1 bình luận 0 reaction 0 người được giao Xem trên GitHub
enhancement
Ngôn ngữ chính
HCL
Star
154
Fork
64
Merge trung bình
4 ngày 12 giờ
Pull request đã merge (30 ngày)
9

Mô tả

If I `regctl image copy --referrers ghcr.io/cloudnative-pg/postgresql:18.4-standard-trixie private.goharbor.instance.com/cloudnative-pg/image:18.4`, the top level view appears like this with a green checkmark:
Image
but if I click the "view this OCI index's artifact list" I get this:
Image
so the architecture-specific images aren't signed. This means I can't enable the feature in Harbor that prevents downloads of non-cosigned images since the images from this repository aren't signed recursively.

Is there a reason only the top manifest is signed, or would it be possible to add `--recursive` to the `cosign sign` command that produces the release images in this organization?

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Tìm cấu hình release chạy lệnh `cosign sign` cho các image PostgreSQL và kiểm tra cách các index đa kiến trúc được xử lý. Xác minh danh sách artifact OCI thu được trong Harbor, bao gồm từng image dành riêng cho một kiến trúc, và xác nhận rằng release workflow vẫn hoàn tất thành công.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
docker, postgresql
Lĩnh vực
devops, release, security
Loại issue
Tính năng
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
48/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.