Skip to content

☂️ Introduce Artifact Signing #283

Description

@Gerrit91

Description

As a result of #235, we want to introduce image signing using cosign. Some images (especially deployment images) are already signed.

The signing process needs to be integrated in all our CI pipelines. To make this more bullet-proof for the future, we introduced reusable workflows in https://github.com/metal-stack/actions-common.

We should also add image digests to the release vector as discussed from this issue in order to make the verification cleaner:

So we need to adapt these to the following repositories:

Docker Images

Binary (optional)

OCI Images

Metadata

Metadata

Assignees

Labels

area: complianceAffects the compliance area.area: deploymentAffects the deployment area.requires docs updateFor merging this pull request, an update in metal-stack.io/docs is required.

Projects

Status
Umbrella
Status
In Progress

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions