fix(cosign): prefer preinstalled cosign and syft over downloading them #55
No reviewers
Labels
No labels
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
webgrip/workflows!55
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/sign-job-external-deps"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The signing job reaches the public internet twice before it signs anything, and both reaches have now taken it down:
received HTTP status=000fetching the releasesearching log query: connection reset by peerThe cosign one is not our doing
Worth stating precisely, because the obvious diagnosis is wrong. Both
cosign signandcosign attesthere already pass--tlog-upload=false, and Kyverno's policy setsrekor.ignoreTlog: trueto match — with a comment saying it must, or Enforce would reject correctly-signed images.The Rekor call comes from inside
cosign-installer: it downloads the requested binary and verifies it withverify-blob, which consults the transparency log.A reset there fails the install, and the release loses its signature.
What this changes
Adds the seam the real fix needs: a preinstalled binary is preferred, exactly as the helm-using workflows already do.
It is a no-op today — the ci-runner image ships neither binary. What it buys is that baking cosign and syft into that image becomes a one-liner elsewhere with no further edit here, and the signing path then stops depending on github.com and sigstore entirely. That image lives in another repo and is the actual fix.
One alternative rejected, not overlooked
The installer short-circuits when the requested version equals its own bootstrap:
Bootstrap is v3.0.6, verified by SHA-256 and never touching Rekor. So requesting v3.0.6 instead of v2.4.3 would dodge this today, with no image change.
It also moves the signing path from cosign v2 to v3 under a Kyverno policy that verifies these signatures and their CycloneDX attestation. That is a deliberate upgrade with its own validation, not something to do as a side effect of a flake fix. Flagged here so the option is on the table rather than lost.