-
Notifications
You must be signed in to change notification settings - Fork 2
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add signed server image to attestation conditions #7
Comments
Just a thought, but we could serve a Docker image ourselves (linked to a release of this repository) that users have access to. That way, we could hard-code the SHA digest of the image into the authorisation script, which helps ensure security. It would also eliminate the workload author role for users. How we would host this remains to be seen of course. |
Great idea. We can make repos public in Artifact Registry |
Or use our organisational Dockerhub site |
We would want some sort of long-term assurance, so the Dockerhub is probably preferable. Can we run an image from there on GCP? Probably best to just chat this over next week 😸 |
No description provided.
The text was updated successfully, but these errors were encountered: