Repository navigation
Sign Docker images and record max-mode provenance - #312
Merged
Merged
Conversation
The agents sign every image they push with cosign 3.1.3, using a Cloud KMS key they reach as the bob service account and find through BOB_COSIGN_KEY. `sign.sh` signs the digest of the index that `docker push` or `docker buildx imagetools create` produced, once per per-arch image and once per manifest. cosign stores the signature as an OCI referrer, which Docker Hub supports, so no tags are added to the repositories Bob reconciles, and records it in the public Rekor log. The digest is hashed from `imagetools inspect --raw` because buildx 0.17.1 ignores a `--format` template. `docker build` records provenance in max mode, which adds the build-arg values (Elixir, OTP and OS versions, which aren't secret) and the Dockerfile to the attestation BuildKit already attaches. The README documents verifying an image against cosign.pub and reading its provenance.
ericmj
marked this pull request as ready for review
October 7, 2026 13:50
cosign.pub is version 1 of projects/hexpm-prod/locations/us-east4/keyRings/bob/cryptoKeys/cosign, created by hexpm/hexpm-ops#386.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The agents sign every image they push with cosign 3.1.3, using a Cloud KMS key they reach as the bob service account and find through BOB_COSIGN_KEY.
sign.shsigns the digest of the index thatdocker pushordocker buildx imagetools createproduced, once per per-arch image and once per manifest. cosign stores the signature as an OCI referrer, which Docker Hub supports, so no tags are added to the repositories Bob reconciles, and records it in the public Rekor log. The digest is hashed fromimagetools inspect --rawbecause buildx 0.17.1 ignores a--formattemplate.docker buildrecords provenance in max mode, which adds the build-arg values (Elixir, OTP and OS versions, which aren't secret) and the Dockerfile to the attestation BuildKit already attaches.The README documents verifying an image against cosign.pub and reading its provenance.
cosign.pubis version 1 of the key created by https://github.com/hexpm/hexpm-ops/pull/386, which is applied and has putBOB_COSIGN_KEYin bob-config. The agents read bob-config in the sameansible/bob-deploy.ymlrun that deploys this image.