Skip to content

[FEATURE] sign images #738

Open
Open
@balu212

Description

@balu212

Is your feature request related to a problem? Please describe.
No

Describe the solution you'd like
As both, controller and injector potentially handle critical secrets, it would be great to validate the pulled images so one can be sure, there is no sideloaded image in use.

Could you therefore sign the container images?
A possible option would be to use cosign for that:
https://github.com/avisi-cloud/cosign-tutorial?tab=readme-ov-file#using-github-actions

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions