diff --git a/.github/chainguard/README.md b/.github/chainguard/README.md new file mode 100644 index 0000000..58b406a --- /dev/null +++ b/.github/chainguard/README.md @@ -0,0 +1,17 @@ +# Production export-wolfi trust + +Export writes only wolfi-staging; publication reads only wolfi-staging. + +These policies are part of [OS-2867](https://linear.app/chainguard/issue/OS-2867). +Follow the [production runbook](https://github.com/chainguard-dev/mono/blob/main/env/enforce.dev/iac/400-export-wolfi/README.md). + +Merge after staging memory acceptance and confirmed paused production +infrastructure deployment. These policies bind dedicated production service +accounts by their numeric `uniqueId`. Reconfirm the subjects against the stage's +`octosts_policies` output and obtain review before merge. If an account is +recreated, update its exact subject and repeat the policy checks and review. + +The three runtime-policy PRs can merge in parallel once their exact subjects are +reviewed. Keep both new schedules paused while installing grants. Complete the +single-writer handover and signed-history proof before merging activation. Runtime +accounts have no git-export access; mono's existing build policy handles direct ko. diff --git a/.github/chainguard/export-wolfi-export.sts.yaml b/.github/chainguard/export-wolfi-export.sts.yaml new file mode 100644 index 0000000..a30f50b --- /dev/null +++ b/.github/chainguard/export-wolfi-export.sts.yaml @@ -0,0 +1,9 @@ +# Production OS-2867: bind the dedicated account by its numeric uniqueId. +# Re-review this subject if the service account is recreated. +# Google service account: export-wolfi@prod-enforce-fabc.iam.gserviceaccount.com +issuer: https://accounts.google.com +subject: "100496071258544612791" +repositories: + - wolfi-staging +permissions: + contents: write diff --git a/.github/chainguard/export-wolfi-publish-read.sts.yaml b/.github/chainguard/export-wolfi-publish-read.sts.yaml new file mode 100644 index 0000000..b74b975 --- /dev/null +++ b/.github/chainguard/export-wolfi-publish-read.sts.yaml @@ -0,0 +1,9 @@ +# Production OS-2867: bind the dedicated account by its numeric uniqueId. +# Re-review this subject if the service account is recreated. +# Google service account: export-wolfi-publish@prod-enforce-fabc.iam.gserviceaccount.com +issuer: https://accounts.google.com +subject: "111686246305885758377" +repositories: + - wolfi-staging +permissions: + contents: read