Releases: krax1337/notation-aws-verifier
Releases · krax1337/notation-aws-verifier
Release list
v1.0.0
First release of notation-aws-verifier, forked from
nirmata/kyverno-notation-aws at commit b0677e4.
Added
--logFormatflag (textorjson) (upstream #471).--tokenReviewAudiencesflag for Kyverno tokens minted with a custom audience (upstream #485).--versionflag; the version is also logged at startup.- Chart:
replicaCount,resources,podDisruptionBudget,topologySpreadConstraints,
priorityClassName,podAnnotations,podLabels,extraArgs,extraEnv,logLevel,
logFormat,cache.*,tokenReview.*,defaultTrustPolicy,service.*,configMap.data,
image.digest,image.pullSecrets(upstream #459). - Multi-arch (linux/amd64, linux/arm64) images with a native signer plugin per architecture.
Changed
- Renamed the Go module to
github.com/krax1337/notation-aws-verifier, the container image to
ghcr.io/krax1337/notation-aws-verifier, and the Helm chart tonotation-aws-verifier
(published atoci://ghcr.io/krax1337/charts/notation-aws-verifier). The CRD API group
notation.nirmata.iois unchanged for drop-in migration. - Inlined the unmaintained
github.com/nirmata/kyverno-notation-verifierv1.1.0 library underinternal/. - The AWS Signer plugin is built from source (pinned, checksum-verified) instead of downloaded
as a prebuilt amd64-only binary. This fixes EKS Pod Identity (only loopback hosts are allowed). - Updated Go to 1.26.8 and all dependencies (Kubernetes 0.37, controller-runtime 0.25,
Kyverno 1.19, notation-go 1.3, ristretto v2). - Per-request logs moved from
infotodebug. - Unauthenticated callers get
401and unauthorized callers403(previously406). - Chart: all resources are named from the release fullname; the Deployment, ServiceAccount and
Service no longer disagree for non-default release names. - Chart: hardcoded
--debugremoved. - Chart: RBAC trimmed to what the service uses;
system:auth-delegatorbinding replaced by a
tokenreviewscreate rule. - Chart:
readOnlyRootFilesystem: true, UID/GID 65532, CRDs annotated with
helm.sh/resource-policy: keepso uninstalling does not delete trust resources.
Fixed
- Memory growth under load (upstream #482): conditions were evaluated in one Kyverno context
shared by all concurrent requests, attestation layer readers were never closed, the cache
was effectively unbounded (MaxCost1 GiB with zero item cost), and every request built new
ECR/GCR/ACR credential helpers. - Default
--cacheTTLDurationSecondswas 3.6e12 seconds instead of 3600. - Panic on an
Authorizationheader without theBearerprefix. - With several replicas, deleting a TrustPolicy or TrustStore left stale files on the replicas
that did not handle the finalizer; reconciles now rebuild state from the full list. - Trust policy/store file write errors were ignored; files are now written atomically.
Stopcould deadlock on shutdown; the plain HTTP server had no timeouts.- Plugin setup failed after a container restart with a persisted
emptyDir. - Chart:
image.pullPolicyis honored,AWS_REGIONis quoted, probe blocks no longer render
stray whitespace, the Helm test pod renders,serviceAccount.enabled=falseworks.
Security
- Kyverno service account bearer tokens were logged at
infoon every request; they are no
longer logged. - The caller-supplied
metadatafield (kyverno-notation-aws.io/verify-imagesannotation) no
longer skips verification; a Pod's creator could set it to bypass signature checks. - Request bodies are size-limited.
- Plugin binaries are installed
0755instead of0777. - Release images and charts are signed with cosign (keyless) and ship SLSA build provenance
and SBOM attestations.
Container image
ghcr.io/krax1337/notation-aws-verifier:v1.0.0
Helm chart
helm install notation-aws-verifier oci://ghcr.io/krax1337/charts/notation-aws-verifier \
--version 1.0.0 -n notation-aws-verifier --create-namespace
See SECURITY.md to verify signatures and provenance.