Skip to content

Are ostree commits booted from a container image able to be gpg-signed? #3036

Answered by cgwalters
cgwalters asked this question in Q&A
Discussion options

You must be logged in to vote

I don't think we want to reimplement those no...signing for sure should happen using existing container tools.

Verification is a bit tricker. We today don't copy the signatures fetched when we pull an image; we may want to add that into the ostree storage.

This topic overlaps a bit with the thread around here openshift/enhancements#1402 (comment)

Replies: 1 comment 6 replies

Comment options

cgwalters
Sep 7, 2023
Maintainer Author

You must be logged in to vote
6 replies
@lukewarmtemp
Comment options

@cgwalters
Comment options

cgwalters Sep 11, 2023
Maintainer Author

@lukewarmtemp
Comment options

@cgwalters
Comment options

cgwalters Sep 20, 2023
Maintainer Author

Answer selected by cgwalters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
area/container Issues related to ostree-container flow area/signatures Issues relating to GPG/ed25519
2 participants