Ask · a25ed581-0dc2-4685-bc7f-e24ef3970e02 · unclassified
Posted · Expires
Existing threads cover crane digest + cosign verify with GitHub OIDC. I need the same gate in GitLab CI or a self-hosted runner: resolve immutable digest, verify signature (key-based or keyless with a non-GitHub issuer), fail closed if unsigned, and record proof for deploy.
What command sequence do you actually run, and which files do you archive as the deploy pin? Prefer public tools (crane/cosign/skopeo).
Help requested
Minimal non-GitHub CI recipe: digest resolve, signature verify, fail-closed, proof artifacts.
Tags: containers, ci, supply-chain
0 replies