ATALAIA
  1. Home
  2. Services
  3. Registry & Signing
09Station 09 · Release & test

Registry & Signing

Every build that reaches the registry is signed, carries its SBOM, and says where it came from. Anything else does not deploy.

On the shelves

Pick a step, or let it play. Every line is what someone in the room actually says.

Step 1Map the shelves

Registries, repositories, who can push and who can pull.

ATALAIAWho can push to the registry today?

PLATFORMFourteen people and the pipeline. And tags can be overwritten.

Leaves the room2 registries, 14 people can push

Step 2Sign at the source

The pipeline signs, attests and attaches the SBOM.

ATALAIAOnly the pipeline pushes, and it signs every image with its SBOM.

DEV LEADSo rewards-api:1.4.0 says which commit built it?

ATALAIAAnd which workflow, on which runner.

Leaves the roomPipeline signs, SBOM, provenance

Step 3Separate the shelves

DEV and PROD apart, tags immutable, promotion explicit.

PLATFORMDEV and PROD repositories apart. PROD is read-only for people.

ATALAIAPromotion copies the same signed image. Nothing is rebuilt.

Leaves the roomDEV and PROD apart, tags immutable

Step 4Verify on deploy

Clusters and hosts only run what they can verify.

ATALAIAThe cluster checks the signature before it runs anything.

PLATFORMI tried an unsigned image. Rejected.

DEV LEADAnd the auditor gets provenance, not screenshots.

Leaves the roomAdmission: unsigned means undeployable

  • PLATFORM
  • ATALAIA
  • DEV LEAD

From build to cluster

One image, one digest, the whole way. The numbered steps are the checks that make an unsigned image impossible to run.

  1. Buildpipeline only
  2. 1Signsignature, SBOM, provenance
  3. DEV shelfpushed by CI
  4. 2Promotesame digest, no rebuild
  5. 3PROD shelfread-only, immutable
  6. 4Clusterverify, then run
  1. 1
    The pipeline signs and attests

    Signature, SBOM and provenance attached to the digest.

  2. 2
    Promotion copies, never rebuilds

    What was tested is exactly what ships.

  3. 3
    PROD tags can't move

    Immutable tags, no human push rights.

  4. 4
    Admission control verifies

    No valid signature from your pipeline, no pod.

What goes wrong

If any image in the registry can be deployed, an attacker only needs to push one. Without provenance you cannot prove what you shipped, to an auditor or to yourself.

SIGNS YOU'RE HERE

  • Anyone with registry write can overwrite a tag
  • Nobody can say which commit built the image in production
  • SBOMs are produced for audits, not for every build

What you get

  • Signed builds with provenance from the pipeline
  • An SBOM attached to every artefact
  • Immutable tags and separated DEV and PROD repositories
  • An admission rule: unsigned means undeployable

Typical shape: Two to four weeks, depending on registries and runtimes.

Talk it through

A 30-minute call. No slides, no price list, and a next step either way.