ci(release): sign every OCI artifact as sigstore bundle referrers #282

Open
nalum wants to merge 1 commit from ci/cosign-bundle-referrers into main
Owner

Why

The image job pinned cosign v2 so podman could read the legacy sha256-<digest>.sig tags. The module and manifests jobs already ran v3. One pipeline had two signature layouts, and the image one rode an end-of-life major.

What

  • Every release job installs cosign v3.1.3 (checksum pinned).
  • Every cosign sign writes a sigstore bundle as an OCI referrer of the signed manifest. Forgejo has no referrers API, so the bundle sits behind the OCI 1.1 fallback tag sha256-<digest>. The image job keeps --recursive, so the index and each platform manifest get a bundle.
  • A committed signing config (.gitea/cosign-signing-config.json) names no Rekor, TSA, CA or OIDC service. Every sign and sign-blob passes it. This replaces the deprecated --tlog-upload=false and --use-signing-config=false flags. Without it, v3 uploads to the public Rekor even with --use-signing-config=false (checked: the bundle carried tlogEntries).
  • deploy/flux/README.md and AGENTS.md describe the layout and the verify commands.

Verified

Against registry:2.8 (no referrers API, same as Forgejo 16.0.2) with cosign 3.1.3:

  • Bundles land behind sha256-<digest> tags with artifactType application/vnd.dev.sigstore.bundle.v0.3+json and the subject set. No .sig tags.
  • cosign verify --key cosign.pub --insecure-ignore-tlog=true passes for the index and for a platform manifest.
  • The bundle has no tlogEntries.

Deliberate gaps

  • podman sigstoreSigned reads only the legacy tags and cannot verify the image. Nothing in this repo deploys through podman.
  • Flux needs source-controller 1.8 or newer, which discovers v3 bundles first and legacy tags second. Not run in a cluster here.
  • timoni mod pull --verify=cosign never passes --insecure-ignore-tlog, so it already rejected the tlog-less signatures. The README now says to verify with cosign, then pull.

🤖 Generated with Claude Code

https://claude.ai/code/session_01XwaXghCjPCVKWTbxCMCBop

## Why The image job pinned cosign v2 so podman could read the legacy `sha256-<digest>.sig` tags. The module and manifests jobs already ran v3. One pipeline had two signature layouts, and the image one rode an end-of-life major. ## What - Every release job installs cosign v3.1.3 (checksum pinned). - Every `cosign sign` writes a sigstore bundle as an OCI referrer of the signed manifest. Forgejo has no referrers API, so the bundle sits behind the OCI 1.1 fallback tag `sha256-<digest>`. The image job keeps `--recursive`, so the index and each platform manifest get a bundle. - A committed signing config (`.gitea/cosign-signing-config.json`) names no Rekor, TSA, CA or OIDC service. Every `sign` and `sign-blob` passes it. This replaces the deprecated `--tlog-upload=false` and `--use-signing-config=false` flags. Without it, v3 uploads to the public Rekor even with `--use-signing-config=false` (checked: the bundle carried `tlogEntries`). - `deploy/flux/README.md` and `AGENTS.md` describe the layout and the verify commands. ## Verified Against registry:2.8 (no referrers API, same as Forgejo 16.0.2) with cosign 3.1.3: - Bundles land behind `sha256-<digest>` tags with artifactType `application/vnd.dev.sigstore.bundle.v0.3+json` and the subject set. No `.sig` tags. - `cosign verify --key cosign.pub --insecure-ignore-tlog=true` passes for the index and for a platform manifest. - The bundle has no `tlogEntries`. ## Deliberate gaps - podman `sigstoreSigned` reads only the legacy tags and cannot verify the image. Nothing in this repo deploys through podman. - Flux needs source-controller 1.8 or newer, which discovers v3 bundles first and legacy tags second. Not run in a cluster here. - `timoni mod pull --verify=cosign` never passes `--insecure-ignore-tlog`, so it already rejected the tlog-less signatures. The README now says to verify with cosign, then pull. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01XwaXghCjPCVKWTbxCMCBop
ci(release): sign every OCI artifact as sigstore bundle referrers
All checks were successful
check / commits (pull_request) Successful in 50s
check / go (pull_request) Successful in 3m24s
check / report (pull_request) Successful in 5s
check / web (pull_request) Successful in 5m13s
a34387776f
The image job pinned cosign v2 so podman's sigstoreSigned policy could
read the legacy sha256-<digest>.sig tags, while the module and manifests
jobs already ran v3 and wrote OCI 1.1 referrer bundles. One pipeline,
two signature layouts, and the image one dragged an end-of-life major.

Every job now runs cosign v3.1.3 and writes the sigstore bundle as an
OCI referrer of the signed manifest (artifactType
application/vnd.dev.sigstore.bundle.v0.3+json, subject = the digest).
Forgejo has no referrers API, so the client falls back to the OCI 1.1
tag schema: one sha256-<digest> index per subject listing its bundles.
Verified end to end against registry:2.8 (same gap) with cosign
3.1.3: --recursive still signs the index and every platform manifest,
and cosign verify finds the bundles by key with the tlog check off.

Offline signing no longer leans on --tlog-upload=false, which v3
deprecates: a committed signing config with no Rekor, TSA, CA or OIDC
services is passed to every sign and sign-blob. Without it v3 uploads
to the public Rekor even with --use-signing-config=false (checked: the
bundle carried a tlogEntries block).

Deliberately dropped: podman's sigstoreSigned policy reads only the
legacy tag layout, so podman can no longer verify the image. Nothing in
this repo deploys through podman; the consumers are Flux (source-
controller 1.8+ discovers v3 bundles first, legacy tags second) and
cosign itself.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XwaXghCjPCVKWTbxCMCBop

Test report

Suite Tests Result Skipped
Unit 1440 ✅ pass 1
Integration 133 ✅ pass —

Coverage: 27.0%

Updated by the check workflow · commit a34387776f

<!-- ci-test-report --> ## Test report | Suite | Tests | Result | Skipped | | --- | --: | --- | --: | | Unit | 1440 | ✅ pass | 1 | | Integration | 133 | ✅ pass | — | **Coverage:** 27.0% <sub>Updated by the check workflow · commit a34387776fdb02b370721de79425bb9e2f0634ed</sub>
All checks were successful
check / commits (pull_request) Successful in 50s
Required
Details
check / go (pull_request) Successful in 3m24s
Required
Details
check / report (pull_request) Successful in 5s
Required
Details
check / web (pull_request) Successful in 5m13s
Required
Details
This pull request doesn't have enough approvals yet. 0 of 1 approvals granted.
This branch is out-of-date with the base branch
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin ci/cosign-bundle-referrers:ci/cosign-bundle-referrers
git switch ci/cosign-bundle-referrers
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app!282
No description provided.