Skip to content
This repository was archived by the owner on Aug 14, 2020. It is now read-only.
This repository was archived by the owner on Aug 14, 2020. It is now read-only.

Evaluate The Update Framework #211

@philips

Description

@philips

Yesterday @titanous told me we should take a second look at The Update Framework (TUF) for addressing a number of things around the signing that we have wanted including: prevention of downgrade (#168), multiple signers, and key revocation.

There is a go implementation that we can look at over here: https://github.com/flynn/go-tuf

Things that need to be explored:

  • how do we support this as an alternative to GPG signing which is super simple and easy for developers to use?
  • how do we make it easy for a user to maintain a repo of images?
  • how does this impact the current SPEC around discovery?

Helpful blog series to explain the basics:

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions