Uploaded image for project: 'OpenShift Pipelines'
  1. OpenShift Pipelines
  2. SRVKP-3790

Chains shouldn't set chains.tekton.dev/signed = true annotation if signed secret is empty or keyless in configured

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: Critical Critical
    • None
    • None
    • Tekton Chains
    • None
    • False
    • None
    • False
    • Pipelines Sprint 254

      Currently, our operator enables Chains by default. Even though, the secret is empty and chains.tekton.dev/signed = True is set. This is an incorrect behaviour.
      The correct behaviour should be - if the secret is empty and "keyless" is not configured, chains shouldn't sign anything, and thus shouldn't set that annotation.

            Unassigned Unassigned
            rh-ee-ksaha Koustav Saha
            Votes:
            0 Vote for this issue
            Watchers:
            5 Start watching this issue

              Created:
              Updated:
              Resolved: