Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Signed release #1142

Open
mloiseleur opened this issue Jul 26, 2024 · 0 comments
Open

Signed release #1142

mloiseleur opened this issue Jul 26, 2024 · 0 comments
Labels
kind/proposal a proposal that needs to be discussed.

Comments

@mloiseleur
Copy link
Contributor

mloiseleur commented Jul 26, 2024

Proposal

It would be nice if the release of this chart would be signed, for improved traceability and security.

It's a native feature of Helm.

Nowadays with OCI, it's possible to sign with a keyless approach using cosign. There is a documented GH action : https://github.com/sigstore/cosign-installer and simple steps to add

It's integrated into Flux, see here.

Verify can be done with Github integration, see for instance how karpenter chart can be verified.

@mloiseleur mloiseleur added the kind/proposal a proposal that needs to be discussed. label Jul 26, 2024
@mloiseleur mloiseleur changed the title Signed chart Signed release Jul 26, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/proposal a proposal that needs to be discussed.
Projects
None yet
Development

No branches or pull requests

1 participant