Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

October 18, 2021 Community Meeting #38

Closed
SaschaSchwarze0 opened this issue Oct 18, 2021 · 10 comments
Closed

October 18, 2021 Community Meeting #38

SaschaSchwarze0 opened this issue Oct 18, 2021 · 10 comments

Comments

@SaschaSchwarze0
Copy link
Member

  • Please add a topic in this thread and add a link to the Github issue associated with the topic.
  • Please make sure you give folks enough time to review/discuss the topic offline on Github before coming into the meeting
  • (optional) Paste the image of an animal 😸
@SaschaSchwarze0
Copy link
Member Author

We failed on getting the release finished. What do we do now?

@adambkaplan
Copy link
Member

CII Best Practices #35

@adambkaplan
Copy link
Member

Image signing and attestation for Shipwright Builds - shipwright-io/build#886

@imjasonh
Copy link
Contributor

@gabemontero
Copy link
Member

/label community

@openshift-ci
Copy link

openshift-ci bot commented Oct 18, 2021

@gabemontero: The label(s) /label community cannot be applied. These labels are supported: platform/aws, platform/azure, platform/baremetal, platform/google, platform/libvirt, platform/openstack, ga, tide/merge-method-merge, tide/merge-method-rebase, tide/merge-method-squash, px-approved, docs-approved, qe-approved, downstream-change-needed, backport-risk-assessed, cherry-pick-approved

In response to this:

/label community

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@gabemontero
Copy link
Member

/kind community

@openshift-ci
Copy link

openshift-ci bot commented Oct 18, 2021

@gabemontero: The label(s) kind/community cannot be applied, because the repository doesn't have them.

In response to this:

/kind community

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@imjasonh
Copy link
Contributor

We failed on getting the release finished. What do we do now?

@adambkaplan
Copy link
Member

Minutes:

  • Release process, needs improvement:
    • CLI not released, currently blocked on go-releaser PR
    • Build release - workflow created a draft release, not clear what the process is after that. Documentation on this needs improvement.
    • Current plan - update blog post to reference the go install process to get the CLI, update later to use the official binary.
  • CII Best practices
  • Image signing and attestation
    • We have a proof of concept to integrate cosign directly into shipwright to sign the container image.
    • Attestation != image signing. This indicates that "this process created the container image" and signs the document cryptographically.
    • Tekton chains supports TaskRun only right now. Perhaps this can be extended?
    • Consensus - we want first class support for image signing in Shipwright, independent of Tekton Chains.
    • Tekton Chains can handle the attestation - we can work with Tekton Chains working group to improve this for Shipwright (ex - attest the BuildRun in addition to the TaskRun). See Sign other types of artifacts tektoncd/chains#124
    • Another item - sign our own release images with cosign. Process needs some form of secret sharing for the project.
  • Zoom for Shipwright - approved by the CDF.
    • Perhaps direct support for video recordings to YouTube?
    • @adambkaplan created a Shipwright Google account - need to configure bitwarden for maintainers so we can share credentials.
  • Image API for Shipwright merged! Next step is to create a repo for the API and main controller

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants