A08: confirm the live cluster reconciles the cosign-verified OCIRepository #20

Closed
opened 2026-08-13 09:35:05 +00:00 by nalum · 1 comment
Owner

deploy/flux/ocirepository-lihnet.yaml:21-24 carries a cosign verify block. The local-ZOT variant (deploy/flux/ocirepository.yaml) has insecure: true, tag: latest, and no verify block. The kind cluster on the dev laptop is the production family install — if it reconciles the unverified ZOT source, anything that can push to zot:5000 in-cluster controls production deploys.

Fix

  • Check which OCIRepository the live cluster has applied.
  • If it is the ZOT one, either add a verify block or switch to the lihnet source.
  • Consider deleting the unsigned manifest or marking it dev-only in a way flux cannot pick up by accident.

Source: OWASP Top 10 (2025) audit of v1.1.0, 2026-08-13. File references point at the v1.1.0 tree.

`deploy/flux/ocirepository-lihnet.yaml:21-24` carries a cosign `verify` block. The local-ZOT variant (`deploy/flux/ocirepository.yaml`) has `insecure: true`, `tag: latest`, and **no** `verify` block. The kind cluster on the dev laptop is the production family install — if it reconciles the unverified ZOT source, anything that can push to `zot:5000` in-cluster controls production deploys. **Fix** - Check which OCIRepository the live cluster has applied. - If it is the ZOT one, either add a `verify` block or switch to the lihnet source. - Consider deleting the unsigned manifest or marking it dev-only in a way flux cannot pick up by accident. --- Source: OWASP Top 10 (2025) audit of `v1.1.0`, 2026-08-13. File references point at the `v1.1.0` tree.
nalum added reference refs/tags/v1.1.0 2026-08-13 09:37:48 +00:00
Author
Owner

Verification result (2026-08-13): the live kind cluster runs no flux controllers at all — no flux CRDs exist, and the app deployment's image is digest-pinned from the local registry by make deploy (localhost:5000/...@sha256:c9e6344e...). Neither OCIRepository is reconciled, so the unsigned ZOT source is dormant, not a live path.

Residual risk was the manifest being applied by accident someday. The PR marks it DEV-ONLY in a loud header and points the family install at the verified lihnet variant.

🤖 Generated with Claude Code

**Verification result (2026-08-13):** the live kind cluster runs **no flux controllers at all** — no flux CRDs exist, and the app deployment's image is digest-pinned from the local registry by `make deploy` (`localhost:5000/...@sha256:c9e6344e...`). Neither OCIRepository is reconciled, so the unsigned ZOT source is dormant, not a live path. Residual risk was the manifest being applied by accident someday. The PR marks it DEV-ONLY in a loud header and points the family install at the verified lihnet variant. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
nalum closed this issue 2026-08-13 11:32:02 +00:00
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#20
No description provided.