-
Feature
-
Resolution: Unresolved
-
Major
-
None
-
None
-
Product / Portfolio Work
-
None
-
0% To Do, 100% In Progress, 0% Done
-
False
-
-
False
-
None
-
None
-
None
-
None
-
-
None
-
None
-
None
-
None
Feature Overview (aka. Goal Summary)
`oc-mirror v2` mirrors signatures b default.
Goals (aka. expected user outcomes)
- Signature mirroring is enabled by default when running `oc-mirror v2` command. (v1 is deprecated and not accepting new features)
- It is possible to disable signature mirroring by an argument provided
Background
- Sigstore (Cluster)ImagePolicy are going GA in 4.20 via OCPSTRAT-2073.
- OCPSTRAT-1930 is targetted to 4.21 and it is going to add sigstore signatures to core OCP payload and enable verification.
OCPSTRAT-1869in 4.19 enabled oc-mirror with signature mirroring and verification, but was disabled by default dependent on Sigstore is GA on Openshift (see first bullet). Right now it is possible to enable it in oc-mirror by using --remove-signatures=false and --secure-policy=true- We now need to have oc-mirror enable sigstore signature mirroring by default.
Requirements (aka. Acceptance Criteria):
- The user should not specify additional parameters when running oc-mirror command to enable signature mirroring.
Open Questions:
Documentation Considerations
Provide information that needs to be considered and planned so that documentation will meet customer needs. If the feature extends existing functionality, provide a link to its current documentation. Initial completion during Refinement status.
<your text here>
- is depended on by
-
OCPNODE-2950 Validate all OpenShift component images using sigstore
-
- In Progress
-
- split from
-
OCPSTRAT-1417 oc-mirror automatically detects and mirror SigStore-style attachments
-
- New
-
- links to