google / google/go-containerregistry

Sign image builds

Open
#1,219 1 comment 0 reactions 1 assignee Claimed by @jonjohnsonjr View on GitHub
enhancement lifecycle/frozen
Dominant language
Go
Stars
4k
Forks
686
Avg merge
2d 12h
Merged PRs (30d)
26

Description

The images we publish here: https://github.com/google/go-containerregistry/blob/2874338840a65b73444563e6bd3540dd2f9271b0/cloudbuild.yaml#L26-L37

... should all be signed with `cosign`, ideally using the "keyless" flow.

For GCB-based keyless signing we can copy what `distroless` does here: https://github.com/GoogleContainerTools/distroless/blob/3ecf55603e31c8c01b4da2da8dc34a41757b778c/cloudbuild.yaml#L81-L82

... essentially the GCB SA is used to impersonate `keyless@go-containerregistry.iam.gserviceaccount.com` for the identity challenge. Some IAM needs to be configured, and then things just work 😉

---

I believe @jonjohnsonjr has to do this given the requirement that we futz with the GCP stuff, but @dlorenc or I would be happy to help navigate this.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.