fix(cosign): prefer preinstalled cosign and syft over downloading them #55

Merged
ryangr0 merged 1 commit from fix/sign-job-external-deps into main 2026-08-26 09:52:01 +00:00
Owner

The signing job reaches the public internet twice before it signs anything, and both reaches have now taken it down:

run error
syft ploeg 172, 175 received HTTP status=000 fetching the release
cosign ploeg 212 searching log query: connection reset by peer

The cosign one is not our doing

Worth stating precisely, because the obvious diagnosis is wrong. Both cosign sign and cosign attest here already pass --tlog-upload=false, and Kyverno's policy sets rekor.ignoreTlog: true to match — with a comment saying it must, or Enforce would reject correctly-signed images.

The Rekor call comes from inside cosign-installer: it downloads the requested binary and verifies it with verify-blob, which consults the transparency log.

INFO: Using bootstrap cosign to verify signature of desired cosign version
Error: searching log query: read tcp …:443: connection reset by peer

A reset there fails the install, and the release loses its signature.

What this changes

Adds the seam the real fix needs: a preinstalled binary is preferred, exactly as the helm-using workflows already do.

It is a no-op today — the ci-runner image ships neither binary. What it buys is that baking cosign and syft into that image becomes a one-liner elsewhere with no further edit here, and the signing path then stops depending on github.com and sigstore entirely. That image lives in another repo and is the actual fix.

One alternative rejected, not overlooked

The installer short-circuits when the requested version equals its own bootstrap:

if [[ "${input_cosign_release}" == "${bootstrap_version}" ]]; then
  log_info "...nothing else to do"; exit 0
fi

Bootstrap is v3.0.6, verified by SHA-256 and never touching Rekor. So requesting v3.0.6 instead of v2.4.3 would dodge this today, with no image change.

It also moves the signing path from cosign v2 to v3 under a Kyverno policy that verifies these signatures and their CycloneDX attestation. That is a deliberate upgrade with its own validation, not something to do as a side effect of a flake fix. Flagged here so the option is on the table rather than lost.

The signing job reaches the public internet **twice before it signs anything**, and both reaches have now taken it down: | | run | error | |---|---|---| | syft | ploeg 172, 175 | `received HTTP status=000` fetching the release | | cosign | ploeg 212 | `searching log query: connection reset by peer` | ## The cosign one is not our doing Worth stating precisely, because the obvious diagnosis is wrong. Both `cosign sign` and `cosign attest` here **already** pass `--tlog-upload=false`, and Kyverno's policy sets `rekor.ignoreTlog: true` to match — with a comment saying it must, or Enforce would reject correctly-signed images. The Rekor call comes from **inside `cosign-installer`**: it downloads the requested binary and verifies it with `verify-blob`, which consults the transparency log. ``` INFO: Using bootstrap cosign to verify signature of desired cosign version Error: searching log query: read tcp …:443: connection reset by peer ``` A reset there fails the install, and the release loses its signature. ## What this changes Adds the seam the real fix needs: a preinstalled binary is preferred, exactly as the helm-using workflows already do. **It is a no-op today** — the ci-runner image ships neither binary. What it buys is that baking cosign and syft into that image becomes a one-liner elsewhere with no further edit here, and the signing path then stops depending on github.com and sigstore entirely. That image lives in another repo and is the actual fix. ## One alternative rejected, not overlooked The installer short-circuits when the requested version equals its own bootstrap: ```bash if [[ "${input_cosign_release}" == "${bootstrap_version}" ]]; then log_info "...nothing else to do"; exit 0 fi ``` Bootstrap is **v3.0.6**, verified by SHA-256 and never touching Rekor. So requesting v3.0.6 instead of v2.4.3 would dodge this **today**, with no image change. It also moves the signing path from cosign v2 to v3 under a Kyverno policy that verifies these signatures and their CycloneDX attestation. That is a deliberate upgrade with its own validation, not something to do as a side effect of a flake fix. Flagged here so the option is on the table rather than lost.
fix(cosign): prefer preinstalled cosign and syft over downloading them
Some checks failed
docker-build-and-push-registry.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
docker-build-and-push.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
forgejo-distribute.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
github-distribute.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
github-issue-create-by-prompt.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
github-issues-create-by-prompt.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
helm-chart-deploy.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
helm-chart-push.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
helm-charts-deploy.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
helm-charts-push.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
laravel-quality.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
php-application-static-analysis.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
rust-semantic-release.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
semantic-release-monorepo.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
semantic-release.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
setup-repository-bootstrap.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
setup-repository-copilot-files.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
setup-repository-create-from-template.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
spa-preview.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
static-analysis.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
sync-template-files.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
techdocs-deploy-backstage-s3.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
techdocs-deploy-codeberg.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
techdocs-deploy-docs-site.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
techdocs-deploy-gh-pages.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
tests.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
update_mkdocs.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
update_techdocs.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
wordpress-plugin-release-distribute.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
wordpress-plugin-release.yml / Merge pull request 'fix(cosign): prefer preinstalled cosign and syft over downloading them' (#55) from fix/sign-job-external-deps into main (pull_request) Failing after 0s
1102722549
The signing job reaches the public internet twice before it signs anything, and
both reaches have taken it down:

  syft   ploeg runs 172, 175 — `received HTTP status=000` fetching the release
  cosign ploeg run 212 — `searching log query: connection reset by peer`

The cosign one is worth naming precisely, because it is not our doing. Both
`cosign sign` and `cosign attest` here already pass --tlog-upload=false, and
Kyverno's policy sets rekor.ignoreTlog to match. The Rekor call comes from
INSIDE cosign-installer: it downloads the requested binary and verifies it with
`verify-blob`, which consults the transparency log. A reset there fails the
install, and the release loses its signature.

This adds the seam the fix needs: a preinstalled binary is preferred, exactly as
the helm-using workflows already do. It is a NO-OP today — the ci-runner image
ships neither — and it stops the signing path depending on the public internet
the moment they are baked in, with no further edit here. That image change lives
in another repo and is the actual fix; this is what lets it land as a one-liner.

One alternative was rejected rather than overlooked. The installer short-circuits
when the requested version equals its own bootstrap (v3.0.6), verifying by
SHA-256 and never touching Rekor — so asking for v3.0.6 would dodge this today.
It also moves the signing path from cosign v2 to v3 under a Kyverno policy that
verifies these signatures, which is not a change to make as a side effect of a
flake fix.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
webgrip-ci referenced this pull request from a commit 2026-08-26 09:52:55 +00:00
Sign in to join this conversation.
No reviewers
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
webgrip/workflows!55
No description provided.