Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Reject tags in cosigned. #799

Merged
merged 1 commit into from
Sep 25, 2021
Merged

Reject tags in cosigned. #799

merged 1 commit into from
Sep 25, 2021

Conversation

mattmoor
Copy link
Member

This change makes cosigned reject tag references, which can drift after validation has occured rendering the validation we perform ineffective.

This also adds unit test coverage for the bulk of the webhook package.

A subsequent change will introduce a mutating webhook that resolves tags to digests (we still need to validating webhook due to webhook ordering).

Signed-off-by: Matt Moore [email protected]

Ticket Link

Related: #784

Release Note

The cosigned webhook now requires digest references to validate references.

This change makes `cosigned` reject tag references, which can drift after validation has occured rendering the validation we perform ineffective.

This also adds unit test coverage for the bulk of the `webhook` package.

A subsequent change will introduce a mutating webhook that resolves tags to digests (we still need to validating webhook due to webhook ordering).

Related: sigstore#784
Signed-off-by: Matt Moore <[email protected]>
@mattmoor
Copy link
Member Author

cc @dlorenc

mattmoor added a commit to mattmoor/cosign that referenced this pull request Sep 25, 2021
This change introduces a mutating webhook to complement our validating webhook.

The validating webhook in sigstore#799 began rejecting tag reference because tags are mutable and can drift between validation and resolution by the kubelet.  This change introduces a mutating webhook that resolves tags to digests as resources are created, so that users aren't necessarily forced to provide digests, but we get the benefits of them nonetheless.

Fixes: sigstore#784
Signed-off-by: Matt Moore <[email protected]>
@mattmoor mattmoor merged commit f9fa769 into sigstore:main Sep 25, 2021
@mattmoor mattmoor deleted the reject-tags branch September 25, 2021 14:51
@github-actions github-actions bot added this to the v1.3.0 milestone Sep 25, 2021
mattmoor added a commit to mattmoor/cosign that referenced this pull request Sep 25, 2021
This change introduces a mutating webhook to complement our validating webhook.

The validating webhook in sigstore#799 began rejecting tag reference because tags are mutable and can drift between validation and resolution by the kubelet.  This change introduces a mutating webhook that resolves tags to digests as resources are created, so that users aren't necessarily forced to provide digests, but we get the benefits of them nonetheless.

Fixes: sigstore#784
Signed-off-by: Matt Moore <[email protected]>
mattmoor added a commit to mattmoor/cosign that referenced this pull request Sep 25, 2021
This change introduces a mutating webhook to complement our validating webhook.

The validating webhook in sigstore#799 began rejecting tag reference because tags are mutable and can drift between validation and resolution by the kubelet.  This change introduces a mutating webhook that resolves tags to digests as resources are created, so that users aren't necessarily forced to provide digests, but we get the benefits of them nonetheless.

Fixes: sigstore#784
Signed-off-by: Matt Moore <[email protected]>
mattmoor added a commit to mattmoor/cosign that referenced this pull request Sep 25, 2021
This change introduces a mutating webhook to complement our validating webhook.

The validating webhook in sigstore#799 began rejecting tag reference because tags are mutable and can drift between validation and resolution by the kubelet.  This change introduces a mutating webhook that resolves tags to digests as resources are created, so that users aren't necessarily forced to provide digests, but we get the benefits of them nonetheless.

Fixes: sigstore#784
Signed-off-by: Matt Moore <[email protected]>
mattmoor added a commit to mattmoor/cosign that referenced this pull request Sep 25, 2021
This change introduces a mutating webhook to complement our validating webhook.

The validating webhook in sigstore#799 began rejecting tag reference because tags are mutable and can drift between validation and resolution by the kubelet.  This change introduces a mutating webhook that resolves tags to digests as resources are created, so that users aren't necessarily forced to provide digests, but we get the benefits of them nonetheless.

Fixes: sigstore#784
Signed-off-by: Matt Moore <[email protected]>
mattmoor added a commit to mattmoor/cosign that referenced this pull request Sep 25, 2021
This change introduces a mutating webhook to complement our validating webhook.

The validating webhook in sigstore#799 began rejecting tag reference because tags are mutable and can drift between validation and resolution by the kubelet.  This change introduces a mutating webhook that resolves tags to digests as resources are created, so that users aren't necessarily forced to provide digests, but we get the benefits of them nonetheless.

Fixes: sigstore#784
Signed-off-by: Matt Moore <[email protected]>
mattmoor added a commit to mattmoor/cosign that referenced this pull request Sep 25, 2021
This change introduces a mutating webhook to complement our validating webhook.

The validating webhook in sigstore#799 began rejecting tag reference because tags are mutable and can drift between validation and resolution by the kubelet.  This change introduces a mutating webhook that resolves tags to digests as resources are created, so that users aren't necessarily forced to provide digests, but we get the benefits of them nonetheless.

Fixes: sigstore#784
Signed-off-by: Matt Moore <[email protected]>
dlorenc pushed a commit that referenced this pull request Sep 26, 2021
This change introduces a mutating webhook to complement our validating webhook.

The validating webhook in #799 began rejecting tag reference because tags are mutable and can drift between validation and resolution by the kubelet.  This change introduces a mutating webhook that resolves tags to digests as resources are created, so that users aren't necessarily forced to provide digests, but we get the benefits of them nonetheless.

Fixes: #784
Signed-off-by: Matt Moore <[email protected]>
mrjoelkamp pushed a commit to mrjoelkamp/cosign that referenced this pull request Sep 28, 2021
This change makes `cosigned` reject tag references, which can drift after validation has occured rendering the validation we perform ineffective.

This also adds unit test coverage for the bulk of the `webhook` package.

A subsequent change will introduce a mutating webhook that resolves tags to digests (we still need to validating webhook due to webhook ordering).

Related: sigstore#784
Signed-off-by: Matt Moore <[email protected]>
Signed-off-by: Joel Kamp <[email protected]>
mrjoelkamp pushed a commit to mrjoelkamp/cosign that referenced this pull request Sep 28, 2021
This change introduces a mutating webhook to complement our validating webhook.

The validating webhook in sigstore#799 began rejecting tag reference because tags are mutable and can drift between validation and resolution by the kubelet.  This change introduces a mutating webhook that resolves tags to digests as resources are created, so that users aren't necessarily forced to provide digests, but we get the benefits of them nonetheless.

Fixes: sigstore#784
Signed-off-by: Matt Moore <[email protected]>
Signed-off-by: Joel Kamp <[email protected]>
mrjoelkamp pushed a commit to mrjoelkamp/cosign that referenced this pull request Sep 28, 2021
This change makes `cosigned` reject tag references, which can drift after validation has occured rendering the validation we perform ineffective.

This also adds unit test coverage for the bulk of the `webhook` package.

A subsequent change will introduce a mutating webhook that resolves tags to digests (we still need to validating webhook due to webhook ordering).

Related: sigstore#784
Signed-off-by: Matt Moore <[email protected]>
Signed-off-by: Joel Kamp <[email protected]>
mrjoelkamp pushed a commit to mrjoelkamp/cosign that referenced this pull request Sep 28, 2021
This change introduces a mutating webhook to complement our validating webhook.

The validating webhook in sigstore#799 began rejecting tag reference because tags are mutable and can drift between validation and resolution by the kubelet.  This change introduces a mutating webhook that resolves tags to digests as resources are created, so that users aren't necessarily forced to provide digests, but we get the benefits of them nonetheless.

Fixes: sigstore#784
Signed-off-by: Matt Moore <[email protected]>
Signed-off-by: Joel Kamp <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants