A08: confirm the live cluster reconciles the cosign-verified OCIRepository #20
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app#20
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
deploy/flux/ocirepository-lihnet.yaml:21-24carries a cosignverifyblock. The local-ZOT variant (deploy/flux/ocirepository.yaml) hasinsecure: true,tag: latest, and noverifyblock. The kind cluster on the dev laptop is the production family install — if it reconciles the unverified ZOT source, anything that can push tozot:5000in-cluster controls production deploys.Fix
verifyblock or switch to the lihnet source.Source: OWASP Top 10 (2025) audit of
v1.1.0, 2026-08-13. File references point at thev1.1.0tree.Verification result (2026-08-13): the live kind cluster runs no flux controllers at all — no flux CRDs exist, and the app deployment's image is digest-pinned from the local registry by
make deploy(localhost:5000/...@sha256:c9e6344e...). Neither OCIRepository is reconciled, so the unsigned ZOT source is dormant, not a live path.Residual risk was the manifest being applied by accident someday. The PR marks it DEV-ONLY in a loud header and points the family install at the verified lihnet variant.
🤖 Generated with Claude Code