-
Notifications
You must be signed in to change notification settings - Fork 1.9k
OSDOCS#17890: Default enablement of signature mirroring #104833
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
OSDOCS#17890: Default enablement of signature mirroring #104833
Conversation
4c586fd to
5656fa8
Compare
|
🤖 Wed Jan 21 13:33:38 - Prow CI generated the docs preview: |
aguidirh
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hi @snarayan-redhat,
Some suggestions from my side:
I would move the text below from Disabling signature mirroring for oc-mirror plugin v2 to Mirroring and verifying image signatures in oc-mirror plugin v2
By default, signature mirroring is enabled, the oc-mirror plugin v2 mirrors Sigstore tag-based signatures for the following images:
OpenShift Container Platform release images
Operator images
Additional images
Helm charts
Note:
If you do not provide a configuration file, the oc-mirror plugin v2 enables signature mirroring for all images.
To specify a custom configuration directory, use the --registries.d flag.
For more details, see the [containers-registries.d(5)](https://github.com/containers/image/blob/main/docs/containers-registries.d.5.md) manual.
Then on the Disabling signature mirroring for oc-mirror plugin v2
I would keep You can disable signature mirroring for all images by providing the --remove-signatures flag for the oc mirror command. and the Procedures 1 and 2.
5656fa8 to
b6d8734
Compare
aguidirh
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Hi @snarayan-redhat,
Only one comment before giving LGTM to this PR.
b6d8734 to
e07e3f4
Compare
|
/lgtm |
michaelryanpeter
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM. I am not merging because it still has the DRAT/WIP label applied.
e07e3f4 to
89cfd69
Compare
89cfd69 to
a38d088
Compare
|
@snarayan-redhat: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
/lgtm |
|
/label qe-approved |
|
/cherrypick enterprise-4.21 |
|
@snarayan-redhat: new pull request created: #105272 DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
…_signaturemirroring OSDOCS#17890: Default enablement of signature mirroring
…_signaturemirroring OSDOCS#17890: Default enablement of signature mirroring
…_signaturemirroring OSDOCS#17890: Default enablement of signature mirroring
…_signaturemirroring OSDOCS#17890: Default enablement of signature mirroring
…_signaturemirroring OSDOCS#17890: Default enablement of signature mirroring
…_signaturemirroring OSDOCS#17890: Default enablement of signature mirroring
…_signaturemirroring OSDOCS#17890: Default enablement of signature mirroring
Version(s): 4.21
Issue: https://issues.redhat.com/browse/OSDOCS-17890
Link to docs preview: https://104833--ocpdocs-pr.netlify.app/openshift-enterprise/latest/disconnected/about-installing-oc-mirror-v2.html#oc-mirror-signature-mirroring-procedure_about-installing-oc-mirror-v2
QE review:
Additional information: