Step 1Map the shelves
Registries, repositories, who can push and who can pull.
ATALAIAWho can push to the registry today?
PLATFORMFourteen people and the pipeline. And tags can be overwritten.
Leaves the room2 registries, 14 people can push
Step 2Sign at the source
The pipeline signs, attests and attaches the SBOM.
ATALAIAOnly the pipeline pushes, and it signs every image with its SBOM.
DEV LEADSo rewards-api:1.4.0 says which commit built it?
ATALAIAAnd which workflow, on which runner.
Leaves the roomPipeline signs, SBOM, provenance
Step 3Separate the shelves
DEV and PROD apart, tags immutable, promotion explicit.
PLATFORMDEV and PROD repositories apart. PROD is read-only for people.
ATALAIAPromotion copies the same signed image. Nothing is rebuilt.
Leaves the roomDEV and PROD apart, tags immutable
Step 4Verify on deploy
Clusters and hosts only run what they can verify.
ATALAIAThe cluster checks the signature before it runs anything.
PLATFORMI tried an unsigned image. Rejected.
DEV LEADAnd the auditor gets provenance, not screenshots.
Leaves the roomAdmission: unsigned means undeployable
- PLATFORM
- ATALAIA
- DEV LEAD