Skip to content

cosign sign and verify before roll-revision touches the acr image - #310

Merged
gerardrecinto merged 1 commit into
masterfrom
cosign-verify-acr
Sep 11, 2026
Merged

gerardrecinto merged 1 commit into
masterfrom
cosign-verify-acr

Conversation

@gerardrecinto

Copy link
Copy Markdown
Collaborator

signs the image right after it lands in acr, keyless, tied to this workflow's own github actions identity, then verifies before roll-revision points the container app at it. container apps has no admission-controller equivalent to kyverno on plain kubernetes so this sign+verify pair is the actual enforcement point

@gerardrecinto
gerardrecinto merged commit fae5fe4 into master Sep 11, 2026
22 of 23 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant