Add notes about container signing now it's enabled again#882
Add notes about container signing now it's enabled again#882jetstack-bot merged 1 commit intocert-manager:masterfrom
Conversation
|
|
||
| ```console | ||
| curl -sSOL https://cert-manager.io/public-keys/cert-manager-pubkey-2021-09-20.pem | ||
| IMAGE_TAG=v1.8.0 # change as needed |
There was a problem hiding this comment.
note: obviously this tag will fail right now because v1.8.0 hasn't been released, but I didn't want to put an alpha version here and it is clear from the text above that it's supported from v1.8.0 onwards
✅ Deploy Preview for cert-manager-website ready!
To edit notification comments on pull requests, go to your Netlify site settings. |
also remove "skip-signing" from release process Signed-off-by: Ashley Davis <ashley.davis@jetstack.io>
e5d0055 to
357bbcd
Compare
irbekrm
left a comment
There was a problem hiding this comment.
Thanks for documenting how to verify the signatures!
I ran the instructions against v1.8.0-alpha.0 images and all worked as expected:
irbe@workspace$ cosign verify --signature-digest-algorithm sha512 --key cert-manager-pubkey-2021-09-20.pem quay.io/jetstack/cert-manager-webhook:$IMAGE_TAG
Verification for quay.io/jetstack/cert-manager-webhook:v1.8.0-alpha.0 --
The following checks were performed on each of these signatures:
- The cosign claims were validated
- The signatures were verified against the specified public key
/lgtm
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: irbekrm, SgtCoDFish The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
I haven't tested the commands. That sounds like a good improvement. Thanks! /lgtm |
|
/retest |
Also remove "skip-signing" from release process because, y'know, we don't want to skip signing any more 😁