Uploaded image for project: 'Cluster Integration and Delivery'
  1. Cluster Integration and Delivery
  2. CLID-289

As a user I would like to mirror the signatures of the container images

XMLWordPrintable

    • Icon: Epic Epic
    • Resolution: Done
    • Icon: Normal Normal
    • None
    • None
    • oc-mirror
    • Signature Mirroring
    • Product / Portfolio Work
    • OCPSTRAT-1869[Phase 1: Cosign tag-based discovery] oc-mirror v2: Discover and mirror SigStore-style attachments
    • 8% To Do, 8% In Progress, 85% Done
    • False
    • Hide

      None

      Show
      None
    • False
    • Not Selected
    • None
    • 31

      Open Questions:

      • Verifying Third-Party Image Signatures: Support verifying the authenticity and integrity of the non-Red Hat (third-party) image signatures using the public keys.  

                 Question 1: How complex would it be to allow users to specify the location of their public keys in the configuration file or pass them as arguments?

                 Question 2: Is it oc-mirror going to copy the certificate/public key as a resource to the cluster resources folder and ask the customer to apply them? 

                 Question 3: How about certificates?  
                 

      • Catalog images signatures: scenario when we rebuild the catalog

                 Question 1: The signature of the catalog rebuilt is not like the original one since we changed the image completely, how is it going to work? Is the cluster going to fail because the signature is not the one expected? 

       

      • Support the future OCI 1.1 referrer-based approach: 
        Question 1: Is the container image prioritizing this implementation on their side? Do we already have the Jira issue about this implementation?

              rh-ee-aguidi Alex Guidi
              rh-ee-aguidi Alex Guidi
              None
              None
              None
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: