•  
      request #41087 Sign our dev/test Docker images using GitHub ephemeral OIDC token
    Infos
    #41087
    Thomas Gerbet (tgerbet)
    2024-12-05 15:44
    2024-12-05 11:44
    42741
    Details
    Sign our dev/test Docker images using GitHub ephemeral OIDC token

    These images are currently signed using a static key hosted on our HC Vault instance. Given they are hosted on GH and built using GitHub Actions we could sign them using the "keyless" signing mode. It gives us a similar level of trust and we do not need to provide access to our infrastructure.

    Dev tools
    Empty
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2024-12-05
    Attachments
    Empty
    References
    Referencing request #41087
    Referenced by request #41087

    Artifact Tracker v5

    rel #37902 16.3

    Follow-ups