Skip to content

build trillian container to existing release.#715

Merged
dlorenc merged 1 commit intosigstore:mainfrom
k4leung4:rel-trillian
Mar 8, 2022
Merged

build trillian container to existing release.#715
dlorenc merged 1 commit intosigstore:mainfrom
k4leung4:rel-trillian

Conversation

@k4leung4
Copy link
Copy Markdown
Member

@k4leung4 k4leung4 commented Mar 7, 2022

Signed-off-by: Kenny Leung kleung@chainguard.dev

Summary

Add Trillian server and signer container as part of Rekor release.
This would provide a multi-platform image that is signed.
The image from github.com/google/trillian also runs the image as root, when it is not necessary.

Once github.com/google/trillian provides signed images and stops running as root, we should consider moving back to using images from them.

Thanks to @nsmith5 for discovering that the image from github.com/google/trillian runs as root.

Ticket Link

Fixes

Release Note


Signed-off-by: Kenny Leung <kleung@chainguard.dev>
@k4leung4 k4leung4 requested a review from cpanato as a code owner March 7, 2022 23:04
@dlorenc dlorenc merged commit ce7f663 into sigstore:main Mar 8, 2022
@github-actions github-actions bot added this to the v1.0.0 milestone Mar 8, 2022
@k4leung4 k4leung4 deleted the rel-trillian branch March 8, 2022 17:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants