You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It appears that AKS has updated the OIDC Issuer URL format and it no longer matches what Fulcio expects. The AKS cluster that I have running in the East US region has the following OIDC Issuer URL for the workload identity preview:
%~> az aks show -n myCluster -g myGroup --query "oidcIssuerProfile.issuerUrl" -otsv
The behavior of this command has been altered by the following extension: aks-preview
https://eastus.oic.prod-aks.azure.com/****
This may also be a difference in the specific region that the AKS cluster is provisioned in.
Version
cosign: v2.0.0-rc.0
fulcio: Public instance (https://fulcio.sigstore.dev)
The text was updated successfully, but these errors were encountered:
Just tried and it worked! I was able to successfully get a signing certificate from fulcio using cosign on my AKS cluster! Many thanks for the review and help getting this rolled out!
Description
It appears that AKS has updated the OIDC Issuer URL format and it no longer matches what Fulcio expects. The AKS cluster that I have running in the East US region has the following OIDC Issuer URL for the workload identity preview:
This may also be a difference in the specific region that the AKS cluster is provisioned in.
Version
cosign: v2.0.0-rc.0
fulcio: Public instance (
https://fulcio.sigstore.dev
)The text was updated successfully, but these errors were encountered: