feat(oci): index annotations and cosign accessory mirroring #53
No reviewers
Labels
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
webgrip/workflows!53
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "feat/oci-annotations-and-accessory-mirroring"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Two gaps found publishing
webgrip/ploegto GHCR, both invisible until someone looked at the package page. Both new inputs default to off, so every existing caller is unaffected.1.
annotationson the build compositeGHCR links a package to a repository from
org.opencontainers.image.source, and reads it from the manifest — not from the image config. A DockerfileLABELlands in the per-platform config, so ploeg's multi-arch image published with the label correctly set and linked nothing, while its Helm chart (a single manifest, annotated by Helm) linked fine. The label was right and in the wrong place.New
annotationsinput takes buildx's ownLEVEL:key=valueform, parsed exactly likedocker-build-args— one argv element per line, blanks and comment lines dropped. The comment rule is not cosmetic here either:--provenance=mode=maxwould otherwise write a caller's prose into the artifact's own metadata.Annotating at build rather than at copy was measured, not assumed. Against two local registries:
imagetools createpreserves index annotationssha256:4677b0ad…→sha256:4677b0ad…identicalSo one annotation at build reaches Harbor, Forgejo and GHCR, and the identical-digest property the mirroring design rests on is untouched. Annotating at copy would have diverged GHCR's index digest from Harbor's.
2.
copy-accessorieson github-distributeimagetools createcopies the manifest list. BuildKit's SLSA provenance and SBOM ride along inside the index for free — GHCR already has both, confirmed by reading the in-toto predicates back (spdx.dev/Document,slsa.dev/provenance/v1). But cosign's signature and attestations do not: they live as separatesha256-<digest>.sig/.atttags and were being left behind, publishing an unsigned mirror of a signed image.Adds
cosign copy --only=sig,att,sbomafter the image copy, so the image is not pushed twice.Verified end to end: signed an image at one registry,
cosign copyto a different host:port, verified at the destination — passes, because cosign checks the digest.One property worth knowing, recorded on the input: the signature payload keeps the origin reference —
so a policy pinning
docker-referencemust verify against the source registry, not the mirror. Kyverno currently verifies against Harbor, so nothing changes today.Fail-soft on a missing signature: an unsigned source is legitimate (the signing job is independent and may not have run for a given tag), and failing the mirror over it would make the image unavailable rather than merely unverifiable.