Skip to content

chore(ci): sign container images with ddsign#1065

Merged
gh-worker-dd-mergequeue-cf854d[bot] merged 1 commit intomainfrom
tianning.li/SVLS-8644-CI-Sign-Image
Mar 5, 2026
Merged

chore(ci): sign container images with ddsign#1065
gh-worker-dd-mergequeue-cf854d[bot] merged 1 commit intomainfrom
tianning.li/SVLS-8644-CI-Sign-Image

Conversation

@litianningdatadog
Copy link
Copy Markdown
Contributor

@litianningdatadog litianningdatadog commented Mar 5, 2026

Summary

Fixes: https://datadoghq.atlassian.net/browse/SVLS-8644

@litianningdatadog litianningdatadog requested a review from a team as a code owner March 5, 2026 18:34
@litianningdatadog litianningdatadog requested a review from lym953 March 5, 2026 18:34
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dont think this change is needed here

Comment thread .gitlab/templates/pipeline.yaml.tpl
@litianningdatadog litianningdatadog force-pushed the tianning.li/SVLS-8644-CI-Sign-Image branch 3 times, most recently from be42a8e to 8b4c0ed Compare March 5, 2026 20:29
@litianningdatadog litianningdatadog force-pushed the tianning.li/SVLS-8644-CI-Sign-Image branch from 8b4c0ed to 7cab058 Compare March 5, 2026 20:30
Install ddsign in the CI Dockerfile and add image signing to the
`ci image` job, which builds the GitLab CI runner image used to
execute pipeline jobs. Adds the required GitLab OIDC id_token
(aud: image-integrity) and invokes ddsign sign after the push.

Fixes: https://datadoghq.atlassian.net/browse/SVLS-8644
@litianningdatadog litianningdatadog force-pushed the tianning.li/SVLS-8644-CI-Sign-Image branch from 7cab058 to acf020b Compare March 5, 2026 20:32
@gh-worker-dd-mergequeue-cf854d gh-worker-dd-mergequeue-cf854d bot merged commit 1559722 into main Mar 5, 2026
51 checks passed
@gh-worker-dd-mergequeue-cf854d gh-worker-dd-mergequeue-cf854d bot deleted the tianning.li/SVLS-8644-CI-Sign-Image branch March 5, 2026 21:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants