Uploaded image for project: 'OpenShift Container Platform (OCP) Strategy'
  1. OpenShift Container Platform (OCP) Strategy
  2. OCPSTRAT-2507

[Phase 1.1: Cosign support] oc-mirror v2: Enable signature mirroring by default

XMLWordPrintable

    • Product / Portfolio Work
    • None
    • 0% To Do, 100% In Progress, 0% Done
    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Feature Overview (aka. Goal Summary)  

      `oc-mirror v2` mirrors signatures b default.

      Goals (aka. expected user outcomes)

      • Signature mirroring is enabled by default when running `oc-mirror v2` command. (v1 is deprecated and not accepting new features)
      • It is possible to disable signature mirroring by an argument provided 

      Background

      • Sigstore (Cluster)ImagePolicy are going GA in 4.20 via OCPSTRAT-2073
      • OCPSTRAT-1930 is targetted to 4.21 and it is going to add sigstore signatures to core OCP payload and enable verification.
      • OCPSTRAT-1869 in 4.19 enabled oc-mirror with signature mirroring and verification, but was disabled by default dependent on Sigstore is GA on Openshift (see first bullet). Right now it is possible to enable it in oc-mirror by using --remove-signatures=false and --secure-policy=true
      • We now need to have oc-mirror enable sigstore signature mirroring by default.

      Requirements (aka. Acceptance Criteria):

      • The user should not specify additional parameters when  running oc-mirror command to enable signature mirroring.

      Open Questions:

      •  

      Documentation Considerations

      Provide information that needs to be considered and planned so that documentation will meet customer needs.  If the feature extends existing functionality, provide a link to its current documentation. Initial completion during Refinement status.

      <your text here>

       

              rhn-support-mkalinin Marina Kalinin
              rhn-support-mkalinin Marina Kalinin
              None
              None
              None
              None
              Shubha Narayanan Shubha Narayanan
              Derrick Ornelas Derrick Ornelas
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: