Skip to content

[ARTSEC-INT] Instrument runner image build with image-integrity signing#1816

Open
harmonherring-pro wants to merge 1 commit intoDataDog:mainfrom
harmonherring-pro:harmon.herring/artsec-int-image-integrity-signing
Open

[ARTSEC-INT] Instrument runner image build with image-integrity signing#1816
harmonherring-pro wants to merge 1 commit intoDataDog:mainfrom
harmonherring-pro:harmon.herring/artsec-int-image-integrity-signing

Conversation

@harmonherring-pro
Copy link

@harmonherring-pro harmonherring-pro commented Mar 16, 2026

Summary

We'll soon require image-integrity signatures on CI images.

  • Adds ddsign image signing to the build-runner-image and release-runner-image CI jobs
  • Configures GitLab ID tokens (DDSIGN_ID_TOKEN) for both jobs
  • Uses --metadata-file with docker buildx build and crane digest for the release copy to obtain image digests for signing

@harmonherring-pro harmonherring-pro marked this pull request as ready for review March 16, 2026 17:39
@harmonherring-pro harmonherring-pro requested a review from a team as a code owner March 16, 2026 17:39
@harmonherring-pro harmonherring-pro marked this pull request as draft March 16, 2026 17:39
@harmonherring-pro harmonherring-pro marked this pull request as ready for review March 16, 2026 17:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants