Skip to content

chainguard-demo/custom-assembly-as-code

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

14 Commits
 
 
 
 
 
 

Repository files navigation

custom-assembly-as-code

Declarative trigger custom image builds using IaC:

  • Verify integrity of existing image by validating the digital signature with cosign
  • Verify SBOM attestation and list packages
  • Trigger new build using the APKO Overlay YAML in the ca-images-iac folder
  • Adheres to security least privilege by using short-lived ephemeral tokens to:
    • Authenticate to the Chainguard Registry using an assumed identity (using the ambient creds of each workflow invocation)
    • Authenticate to GitHub (using octo-sts in place of a long-lived PAT)

Usage

image

About

Declarative Custom Assembly

Topics

Resources

Security policy

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 3

  •  
  •  
  •