merge feat/cosign-platform-bound-ns (c060c7b1b5) #307
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/cosign-platform-bound-ns"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
vault-build-pipeline-auth-role now binds pipeline-cosign-signer in BOTH workflows-{stackName} AND (static) workflows-platform, so the platform kernel-bake cosign sign step can assume build-pipeline-{tenant} and sign with the shared cosign-ec transit key during dual-run. [0] is patched to workflows-{stackName}; the static [1]=workflows-platform is the transitional dual-run bridge (only alice is deployed), removed when the cosign auth role relocates to the platform singleton at cutover. Refs platform-collapse Phase 2 (gate-prep gap 2).View command line instructions
Manual merge helper
Use this merge commit message when completing the merge manually.
Checkout
From your project repository, check out a new branch and test the changes.