Skip to content

Commit

Permalink
Merge pull request #452 from uselagoon/fix-release-attestation
Browse files Browse the repository at this point in the history
fix: update release workflow to fix attestation logic
  • Loading branch information
smlx authored Jun 11, 2024
2 parents 5379ddc + 92e5a96 commit 0d6fdd5
Show file tree
Hide file tree
Showing 2 changed files with 31 additions and 8 deletions.
38 changes: 30 additions & 8 deletions .github/workflows/release.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -63,20 +63,42 @@ jobs:
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITHUB_SBOM_PATH: ./sbom.spdx.json
# attest archives
- uses: actions/attest-build-provenance@49df96e17e918a15956db358890b08e61c704919 # v1.2.0
with:
subject-path: "dist/*.tar.gz"
# parse artifacts to the format required for image attestation
- run: |
echo "digest=$(echo "$ARTIFACTS" | jq -r '.[]|select(.type=="Docker Manifest")|select(.name|test(":v"))|.extra.Digest')" >> "$GITHUB_OUTPUT"
echo "name=$(echo "$ARTIFACTS" | jq -r '.[]|select(.type=="Docker Manifest")|select(.name|test(":v"))|.name|split(":")[0]')" >> "$GITHUB_OUTPUT"
id: image_metadata
echo "digest=$(echo "$ARTIFACTS" | jq -r '.[]|select(.type=="Docker Manifest")|select(.name|test("ssh-portal:v"))|.extra.Digest')" >> "$GITHUB_OUTPUT"
echo "name=$(echo "$ARTIFACTS" | jq -r '.[]|select(.type=="Docker Manifest")|select(.name|test("ssh-portal:v"))|.name|split(":")[0]')" >> "$GITHUB_OUTPUT"
id: image_metadata_ssh_portal
env:
ARTIFACTS: ${{steps.goreleaser.outputs.artifacts}}
# attest archives
- run: |
echo "digest=$(echo "$ARTIFACTS" | jq -r '.[]|select(.type=="Docker Manifest")|select(.name|test("ssh-portal-api:v"))|.extra.Digest')" >> "$GITHUB_OUTPUT"
echo "name=$(echo "$ARTIFACTS" | jq -r '.[]|select(.type=="Docker Manifest")|select(.name|test("ssh-portal-api:v"))|.name|split(":")[0]')" >> "$GITHUB_OUTPUT"
id: image_metadata_ssh_portal_api
env:
ARTIFACTS: ${{steps.goreleaser.outputs.artifacts}}
- run: |
echo "digest=$(echo "$ARTIFACTS" | jq -r '.[]|select(.type=="Docker Manifest")|select(.name|test("ssh-token:v"))|.extra.Digest')" >> "$GITHUB_OUTPUT"
echo "name=$(echo "$ARTIFACTS" | jq -r '.[]|select(.type=="Docker Manifest")|select(.name|test("ssh-token:v"))|.name|split(":")[0]')" >> "$GITHUB_OUTPUT"
id: image_metadata_ssh_token
env:
ARTIFACTS: ${{steps.goreleaser.outputs.artifacts}}
# attest images
- uses: actions/attest-build-provenance@49df96e17e918a15956db358890b08e61c704919 # v1.2.0
with:
subject-path: "dist/*.tar.gz"
# attest images
subject-digest: ${{steps.image_metadata_ssh_portal.outputs.digest}}
subject-name: ${{steps.image_metadata_ssh_portal.outputs.name}}
push-to-registry: true
- uses: actions/attest-build-provenance@49df96e17e918a15956db358890b08e61c704919 # v1.2.0
with:
subject-digest: ${{steps.image_metadata_ssh_portal_api.outputs.digest}}
subject-name: ${{steps.image_metadata_ssh_portal_api.outputs.name}}
push-to-registry: true
- uses: actions/attest-build-provenance@49df96e17e918a15956db358890b08e61c704919 # v1.2.0
with:
subject-digest: ${{steps.image_metadata.outputs.digest}}
subject-name: ${{steps.image_metadata.outputs.name}}
subject-digest: ${{steps.image_metadata_ssh_token.outputs.digest}}
subject-name: ${{steps.image_metadata_ssh_token.outputs.name}}
push-to-registry: true
1 change: 1 addition & 0 deletions .goreleaser.yaml
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
version: 2
builds:
- &buildDefinition
id: ssh-portal
Expand Down

0 comments on commit 0d6fdd5

Please sign in to comment.