-
Notifications
You must be signed in to change notification settings - Fork 60
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Use TUF instead of env variables. #159
Conversation
Signed-off-by: Ville Aikas <vaikas@chainguard.dev>
Signed-off-by: Ville Aikas <vaikas@chainguard.dev>
Signed-off-by: Ville Aikas <vaikas@chainguard.dev>
Signed-off-by: cpanato <ctadeu@gmail.com>
Signed-off-by: cpanato <ctadeu@gmail.com>
Signed-off-by: Ville Aikas <vaikas@chainguard.dev>
Signed-off-by: Ville Aikas <vaikas@chainguard.dev>
Signed-off-by: Ville Aikas <vaikas@chainguard.dev>
If all works here, I'd like to use this instead of #157 so that we don't need to bring in the additional initContainer. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
lgtm
Signed-off-by: Ville Aikas <vaikas@chainguard.dev>
Codecov Report
@@ Coverage Diff @@
## main #159 +/- ##
==========================================
- Coverage 63.40% 63.05% -0.35%
==========================================
Files 26 26
Lines 2350 2363 +13
==========================================
Hits 1490 1490
- Misses 782 795 +13
Partials 78 78
Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here. |
Thanks so much @cpanato for making kustomize work, super neat! |
Documentation changes here: |
…#151) * Remove dependabot for this fork (sigstore#159) * Add Actions release and attest job (sigstore#147) * update release workflow Signed-off-by: Meredith Lancaster <malancas@github.com> * Grab image digest for attestation step Signed-off-by: Meredith Lancaster <malancas@github.com> * comment Signed-off-by: Meredith Lancaster <malancas@github.com> * update workflow name Signed-off-by: Meredith Lancaster <malancas@github.com> * add release directions Signed-off-by: Meredith Lancaster <malancas@github.com> * undo ko config changes Signed-off-by: Meredith Lancaster <malancas@github.com> * add fork specific options to ko build call Signed-off-by: Meredith Lancaster <malancas@github.com> * Change version format --------- Signed-off-by: Meredith Lancaster <malancas@github.com> Co-authored-by: Cody Soyland <codysoyland@github.com> * set release as target branch (sigstore#161) Signed-off-by: Meredith Lancaster <malancas@github.com> * Add support for Sigstore Bundles using sigstore-go verifier Signed-off-by: Cody Soyland <codysoyland@github.com> * Update docs Signed-off-by: Cody Soyland <codysoyland@github.com> * Rename func Signed-off-by: Cody Soyland <codysoyland@github.com> * Comment on observe timestamp setting Signed-off-by: Cody Soyland <codysoyland@github.com> * Refactor trusted material, add support for default TUF repo in bundle verifier Signed-off-by: Cody Soyland <codysoyland@github.com> * Remove accidental code Signed-off-by: Cody Soyland <codysoyland@github.com> * Fix tlog verification options Signed-off-by: Cody Soyland <codysoyland@github.com> --------- Signed-off-by: Meredith Lancaster <malancas@github.com> Signed-off-by: Cody Soyland <codysoyland@github.com> Co-authored-by: Meredith Lancaster <malancas@users.noreply.github.com>
…#151) * Remove dependabot for this fork (sigstore#159) * Add Actions release and attest job (sigstore#147) * update release workflow Signed-off-by: Meredith Lancaster <malancas@github.com> * Grab image digest for attestation step Signed-off-by: Meredith Lancaster <malancas@github.com> * comment Signed-off-by: Meredith Lancaster <malancas@github.com> * update workflow name Signed-off-by: Meredith Lancaster <malancas@github.com> * add release directions Signed-off-by: Meredith Lancaster <malancas@github.com> * undo ko config changes Signed-off-by: Meredith Lancaster <malancas@github.com> * add fork specific options to ko build call Signed-off-by: Meredith Lancaster <malancas@github.com> * Change version format --------- Signed-off-by: Meredith Lancaster <malancas@github.com> Co-authored-by: Cody Soyland <codysoyland@github.com> * set release as target branch (sigstore#161) Signed-off-by: Meredith Lancaster <malancas@github.com> * Add support for Sigstore Bundles using sigstore-go verifier Signed-off-by: Cody Soyland <codysoyland@github.com> * Update docs Signed-off-by: Cody Soyland <codysoyland@github.com> * Rename func Signed-off-by: Cody Soyland <codysoyland@github.com> * Comment on observe timestamp setting Signed-off-by: Cody Soyland <codysoyland@github.com> * Refactor trusted material, add support for default TUF repo in bundle verifier Signed-off-by: Cody Soyland <codysoyland@github.com> * Remove accidental code Signed-off-by: Cody Soyland <codysoyland@github.com> * Fix tlog verification options Signed-off-by: Cody Soyland <codysoyland@github.com> --------- Signed-off-by: Meredith Lancaster <malancas@github.com> Signed-off-by: Cody Soyland <codysoyland@github.com> Co-authored-by: Meredith Lancaster <malancas@users.noreply.github.com>
…#151) * Remove dependabot for this fork (sigstore#159) * Add Actions release and attest job (sigstore#147) * update release workflow Signed-off-by: Meredith Lancaster <malancas@github.com> * Grab image digest for attestation step Signed-off-by: Meredith Lancaster <malancas@github.com> * comment Signed-off-by: Meredith Lancaster <malancas@github.com> * update workflow name Signed-off-by: Meredith Lancaster <malancas@github.com> * add release directions Signed-off-by: Meredith Lancaster <malancas@github.com> * undo ko config changes Signed-off-by: Meredith Lancaster <malancas@github.com> * add fork specific options to ko build call Signed-off-by: Meredith Lancaster <malancas@github.com> * Change version format --------- Signed-off-by: Meredith Lancaster <malancas@github.com> Co-authored-by: Cody Soyland <codysoyland@github.com> * set release as target branch (sigstore#161) Signed-off-by: Meredith Lancaster <malancas@github.com> * Add support for Sigstore Bundles using sigstore-go verifier Signed-off-by: Cody Soyland <codysoyland@github.com> * Update docs Signed-off-by: Cody Soyland <codysoyland@github.com> * Rename func Signed-off-by: Cody Soyland <codysoyland@github.com> * Comment on observe timestamp setting Signed-off-by: Cody Soyland <codysoyland@github.com> * Refactor trusted material, add support for default TUF repo in bundle verifier Signed-off-by: Cody Soyland <codysoyland@github.com> * Remove accidental code Signed-off-by: Cody Soyland <codysoyland@github.com> * Fix tlog verification options Signed-off-by: Cody Soyland <codysoyland@github.com> --------- Signed-off-by: Meredith Lancaster <malancas@github.com> Signed-off-by: Cody Soyland <codysoyland@github.com> Co-authored-by: Meredith Lancaster <malancas@users.noreply.github.com>
…#151) * Remove dependabot for this fork (sigstore#159) * Add Actions release and attest job (sigstore#147) * update release workflow Signed-off-by: Meredith Lancaster <malancas@github.com> * Grab image digest for attestation step Signed-off-by: Meredith Lancaster <malancas@github.com> * comment Signed-off-by: Meredith Lancaster <malancas@github.com> * update workflow name Signed-off-by: Meredith Lancaster <malancas@github.com> * add release directions Signed-off-by: Meredith Lancaster <malancas@github.com> * undo ko config changes Signed-off-by: Meredith Lancaster <malancas@github.com> * add fork specific options to ko build call Signed-off-by: Meredith Lancaster <malancas@github.com> * Change version format --------- Signed-off-by: Meredith Lancaster <malancas@github.com> Co-authored-by: Cody Soyland <codysoyland@github.com> * set release as target branch (sigstore#161) Signed-off-by: Meredith Lancaster <malancas@github.com> * Add support for Sigstore Bundles using sigstore-go verifier Signed-off-by: Cody Soyland <codysoyland@github.com> * Update docs Signed-off-by: Cody Soyland <codysoyland@github.com> * Rename func Signed-off-by: Cody Soyland <codysoyland@github.com> * Comment on observe timestamp setting Signed-off-by: Cody Soyland <codysoyland@github.com> * Refactor trusted material, add support for default TUF repo in bundle verifier Signed-off-by: Cody Soyland <codysoyland@github.com> * Remove accidental code Signed-off-by: Cody Soyland <codysoyland@github.com> * Fix tlog verification options Signed-off-by: Cody Soyland <codysoyland@github.com> --------- Signed-off-by: Meredith Lancaster <malancas@github.com> Signed-off-by: Cody Soyland <codysoyland@github.com> Co-authored-by: Meredith Lancaster <malancas@users.noreply.github.com> Fix method name Signed-off-by: Cody Soyland <codysoyland@github.com>
Summary
Add two new flags that you can use to specify how to initialize TUF root.
--tuf-mirror
--tuf-root
We then do equivalent of cosign initialize with those.
Release Note
Documentation