diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 8e8fb2e..3f0c019 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -20,6 +20,18 @@ jobs: - uses: sigstore/cosign-installer@v3 - uses: fluxcd/flux2/action@main - uses: stefanprodan/timoni/actions/setup@main + - name: Setup Notation CLI + uses: notaryproject/notation-action/setup@v1 + with: + version: "1.1.0" + - name: Setup Notation signing keys + run: | + mkdir -p ~/.config/notation/localkeys/ + cp ./.notation/signingkeys.json ~/.config/notation/ + cp ./.notation/notation.crt ~/.config/notation/localkeys/ + echo "$NOTATION_KEY" > ~/.config/notation/localkeys/notation.key + env: + NOTATION_KEY: ${{ secrets.NOTATION_SIGNING_KEY }} - name: Setup Go uses: actions/setup-go@v4 with: @@ -109,6 +121,10 @@ jobs: cosign sign ghcr.io/stefanprodan/podinfo:${{ steps.prep.outputs.VERSION }} --yes cosign sign ghcr.io/stefanprodan/charts/podinfo:${{ steps.prep.outputs.VERSION }} --yes cosign sign ghcr.io/stefanprodan/manifests/podinfo:${{ steps.prep.outputs.VERSION }} --yes + notation sign --signature-format cose docker.io/stefanprodan/podinfo:${{ steps.prep.outputs.VERSION }} + notation sign --signature-format cose ghcr.io/stefanprodan/podinfo:${{ steps.prep.outputs.VERSION }} + notation sign --signature-format cose ghcr.io/stefanprodan/charts/podinfo:${{ steps.prep.outputs.VERSION }} + notation sign --signature-format cose ghcr.io/stefanprodan/manifests/podinfo:${{ steps.prep.outputs.VERSION }} - name: Publish base image uses: docker/build-push-action@v5 with: @@ -134,6 +150,8 @@ jobs: echo "$COSIGN_KEY" > /tmp/cosign.key cosign sign -key /tmp/cosign.key ghcr.io/stefanprodan/podinfo-deploy:${{ steps.prep.outputs.VERSION }} --yes cosign sign -key /tmp/cosign.key ghcr.io/stefanprodan/podinfo-deploy:latest --yes + notation sign --signature-format cose ghcr.io/stefanprodan/podinfo-deploy:${{ steps.prep.outputs.VERSION }} + notation sign --signature-format cose ghcr.io/stefanprodan/podinfo-deploy:latest env: COSIGN_PASSWORD: ${{secrets.COSIGN_PASSWORD}} COSIGN_KEY: ${{secrets.COSIGN_KEY}} diff --git a/.gitignore b/.gitignore index 9f48c7a..b70fe02 100644 --- a/.gitignore +++ b/.gitignore @@ -23,3 +23,6 @@ bin/ cue/cue.mod/gen/ cue/go.mod cue/go.sum + +.notation/podinfo.csr +.notation/podinfo.key diff --git a/.notation/README.md b/.notation/README.md new file mode 100644 index 0000000..62181d4 --- /dev/null +++ b/.notation/README.md @@ -0,0 +1,15 @@ +# Podinfo signed releases + +Podinfo release assets such as the Helm chart and the Flux artifact +are published to GitHub Container Registry and are signed with +[Notation](https://github.com/notaryproject/notation). + +## Generate signing keys + +Generate a new signing key pair: + +```sh +openssl genrsa -out podinfo.key 2048 +openssl req -new -key podinfo.key -out podinfo.csr -config codesign.cnf +openssl x509 -req -days 1826 -in podinfo.csr -signkey podinfo.key -out notation.crt -extensions v3_req -extfile codesign.cnf +``` diff --git a/.notation/codesign.cnf b/.notation/codesign.cnf new file mode 100644 index 0000000..5903a3a --- /dev/null +++ b/.notation/codesign.cnf @@ -0,0 +1,18 @@ +[ req ] +default_bits = 2048 +default_keyfile = privatekey.pem +distinguished_name = req_distinguished_name +req_extensions = v3_req +prompt = no + +[ req_distinguished_name ] +C = RO +ST = BU +L = Bucharest +O = Notary +CN = stefanprodan.com + +[ v3_req ] +keyUsage = critical,digitalSignature +extendedKeyUsage = critical,codeSigning +#subjectKeyIdentifier = hash diff --git a/.notation/notation.crt b/.notation/notation.crt new file mode 100644 index 0000000..e1ad1da --- /dev/null +++ b/.notation/notation.crt @@ -0,0 +1,21 @@ +-----BEGIN CERTIFICATE----- +MIIDbDCCAlSgAwIBAgIUP7zhmTw5XTWLcgBGkBEsErMOkz4wDQYJKoZIhvcNAQEL +BQAwWjELMAkGA1UEBhMCUk8xCzAJBgNVBAgMAkJVMRIwEAYDVQQHDAlCdWNoYXJl +c3QxDzANBgNVBAoMBk5vdGFyeTEZMBcGA1UEAwwQc3RlZmFucHJvZGFuLmNvbTAe +Fw0yNDAyMjUxMDAyMzZaFw0yOTAyMjQxMDAyMzZaMFoxCzAJBgNVBAYTAlJPMQsw +CQYDVQQIDAJCVTESMBAGA1UEBwwJQnVjaGFyZXN0MQ8wDQYDVQQKDAZOb3Rhcnkx +GTAXBgNVBAMMEHN0ZWZhbnByb2Rhbi5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IB +DwAwggEKAoIBAQDtH4oPi3SyX/DGv6NdjIvmApvD9eeSgsmHdwpAly8T9D2me+fx +Z+wRNJmq4aq/A1anX+Sg28iwHzV+1WKpsHnjYzDAJSEYP2S8A5H1nGRKUoibdijw +C3QBh5C75rjF/tmZVSX/Vgbf3HJJEsF4WUxWabLxoV2QLo7UlEsQd9+bSeKNMncx +1+E6FdbRCrYo90iobvZJ8K/S2zCWq/JTeHfTnmSEDhx6nMJcaSjvMPn3zyauWcQw +dDpkcaGiJ64fEJRT2OFxXv9u+vDmIMKzo/Wjbd+IzFj6YY4VisK88aU7tmDelnk5 +gQB9eu62PFoaVsYJp4VOhblFKvGJpQwbWB9BAgMBAAGjKjAoMA4GA1UdDwEB/wQE +AwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDAzANBgkqhkiG9w0BAQsFAAOCAQEA +6x+C6hAIbLwMvkNx4K5p7Qe/pLQR0VwQFAw10yr/5KSN+YKFpon6pQ0TebL7qll+ +uBGZvtQhN6v+DlnVqB7lvJKd+89isgirkkews5KwuXg7Gv5UPIugH0dXISZU8DMJ +7J4oKREv5HzdFmfsUfNlQcfyVTjKL6UINXfKGdqNNxXxR9b4a1TY2JcmEhzBTHaq +ZqX6HK784a0dB7aHgeFrFwPCCP4M684Hs7CFbk3jo2Ef4ljnB5AyWpe8pwCLMdRt +UjSjL5xJWVQvRU+STQsPr6SvpokPCG4rLQyjgeYYk4CCj5piSxbSUZFavq8v1y7Y +m91USVqfeUX7ZzjDxPHE2A== +-----END CERTIFICATE----- diff --git a/.notation/signingkeys.json b/.notation/signingkeys.json new file mode 100644 index 0000000..662defe --- /dev/null +++ b/.notation/signingkeys.json @@ -0,0 +1,10 @@ +{ + "default": "stefanprodan.com", + "keys": [ + { + "name": "stefanprodan.com", + "keyPath": "/home/runner/.config/notation/localkeys/notation.key", + "certPath": "/home/runner/.config/notation/localkeys/notation.crt" + } + ] +} diff --git a/.notation/trustpolicy.json b/.notation/trustpolicy.json new file mode 100644 index 0000000..3daab53 --- /dev/null +++ b/.notation/trustpolicy.json @@ -0,0 +1,19 @@ +{ + "version": "1.0", + "trustPolicies": [ + { + "name": "stefanprodan.com", + "registryScopes": [ + "ghcr.io/stefanprodan/podinfo-deploy", + "ghcr.io/stefanprodan/charts/podinfo" + ], + "signatureVerification": { + "level" : "strict" + }, + "trustStores": [ "ca:stefanprodan.com" ], + "trustedIdentities": [ + "x509.subject: C=RO, ST=BU, L=Bucharest, O=Notary, CN=stefanprodan.com" + ] + } + ] +}