Skip to content

Sign Docker images and record max-mode provenance - #312

Merged
ericmj merged 2 commits into
mainfrom
sign-docker-images
Oct 7, 2026
Merged

ericmj merged 2 commits into
mainfrom
sign-docker-images

Conversation

@ericmj

@ericmj ericmj commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

The agents sign every image they push with cosign 3.1.3, using a Cloud KMS key they reach as the bob service account and find through BOB_COSIGN_KEY. sign.sh signs the digest of the index that docker push or docker buildx imagetools create produced, once per per-arch image and once per manifest. cosign stores the signature as an OCI referrer, which Docker Hub supports, so no tags are added to the repositories Bob reconciles, and records it in the public Rekor log. The digest is hashed from imagetools inspect --raw because buildx 0.17.1 ignores a --format template.

docker build records provenance in max mode, which adds the build-arg values (Elixir, OTP and OS versions, which aren't secret) and the Dockerfile to the attestation BuildKit already attaches.

The README documents verifying an image against cosign.pub and reading its provenance.

cosign.pub is version 1 of the key created by https://github.com/hexpm/hexpm-ops/pull/386, which is applied and has put BOB_COSIGN_KEY in bob-config. The agents read bob-config in the same ansible/bob-deploy.yml run that deploys this image.

The agents sign every image they push with cosign 3.1.3, using a Cloud KMS key they reach as the bob service account and find through BOB_COSIGN_KEY. `sign.sh` signs the digest of the index that `docker push` or `docker buildx imagetools create` produced, once per per-arch image and once per manifest. cosign stores the signature as an OCI referrer, which Docker Hub supports, so no tags are added to the repositories Bob reconciles, and records it in the public Rekor log. The digest is hashed from `imagetools inspect --raw` because buildx 0.17.1 ignores a `--format` template.

`docker build` records provenance in max mode, which adds the build-arg values (Elixir, OTP and OS versions, which aren't secret) and the Dockerfile to the attestation BuildKit already attaches.

The README documents verifying an image against cosign.pub and reading its provenance.
@ericmj
ericmj marked this pull request as ready for review October 7, 2026 13:50
cosign.pub is version 1 of projects/hexpm-prod/locations/us-east4/keyRings/bob/cryptoKeys/cosign, created by hexpm/hexpm-ops#386.
@ericmj
ericmj merged commit 38e0b5f into main Oct 7, 2026
4 checks passed
@ericmj
ericmj deleted the sign-docker-images branch October 7, 2026 14:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant