From de356310faf2eea2f83adbfb8b7605fe0032ff7e Mon Sep 17 00:00:00 2001 From: Joe Borg Date: Mon, 28 Sep 2026 12:50:19 -0400 Subject: [PATCH 1/2] chore(auth): prepare production Wolfi destination grants --- .github/chainguard/README.md | 17 +++++++++++++++++ .github/chainguard/export-wolfi-export.sts.yaml | 9 +++++++++ .../export-wolfi-publish-read.sts.yaml | 9 +++++++++ 3 files changed, 35 insertions(+) create mode 100644 .github/chainguard/README.md create mode 100644 .github/chainguard/export-wolfi-export.sts.yaml create mode 100644 .github/chainguard/export-wolfi-publish-read.sts.yaml diff --git a/.github/chainguard/README.md b/.github/chainguard/README.md new file mode 100644 index 0000000..9e5cfd3 --- /dev/null +++ b/.github/chainguard/README.md @@ -0,0 +1,17 @@ +# Production export-wolfi trust + +Export writes only wolfi-staging; publication reads only wolfi-staging. + +These policies are part of [OS-2867](https://linear.app/chainguard/issue/OS-2867). +Follow the [production runbook](https://github.com/chainguard-dev/mono/blob/main/env/enforce.dev/iac/400-export-wolfi/README.md). + +Merge after staging memory acceptance and paused production infrastructure +provisioning. Replace each `UNPROVISIONED-...` subject with the created account's +numeric `uniqueId` from the stage's `octosts_policies` output; re-run policy checks +and obtain review before merge. The placeholder deliberately matches no Google +service account and must never be treated as a working runtime grant. + +The three runtime-policy PRs can merge in parallel once their exact subjects are +reviewed. Keep both new schedules paused while installing grants. Complete the +single-writer handover and signed-history proof before merging activation. Runtime +accounts have no git-export access; mono's existing build policy handles direct ko. diff --git a/.github/chainguard/export-wolfi-export.sts.yaml b/.github/chainguard/export-wolfi-export.sts.yaml new file mode 100644 index 0000000..56d4dd5 --- /dev/null +++ b/.github/chainguard/export-wolfi-export.sts.yaml @@ -0,0 +1,9 @@ +# Production OS-2867: replace this nonmatching subject after paused provisioning. +# Do not merge until the account's numeric uniqueId has been verified and reviewed. +# Expected account: export-wolfi@prod-enforce-fabc.iam.gserviceaccount.com +issuer: https://accounts.google.com +subject: "UNPROVISIONED-export-wolfi-prod-OS-2867" +repositories: + - wolfi-staging +permissions: + contents: write diff --git a/.github/chainguard/export-wolfi-publish-read.sts.yaml b/.github/chainguard/export-wolfi-publish-read.sts.yaml new file mode 100644 index 0000000..d1dd298 --- /dev/null +++ b/.github/chainguard/export-wolfi-publish-read.sts.yaml @@ -0,0 +1,9 @@ +# Production OS-2867: replace this nonmatching subject after paused provisioning. +# Do not merge until the account's numeric uniqueId has been verified and reviewed. +# Expected account: export-wolfi-publish@prod-enforce-fabc.iam.gserviceaccount.com +issuer: https://accounts.google.com +subject: "UNPROVISIONED-export-wolfi-publish-prod-OS-2867" +repositories: + - wolfi-staging +permissions: + contents: read From a9f73f27c4d2bbd95232fdc62864b4ff665df7d2 Mon Sep 17 00:00:00 2001 From: Joe Borg Date: Tue, 29 Sep 2026 09:07:11 -0400 Subject: [PATCH 2/2] chore(auth): bind provisioned production Wolfi identities --- .github/chainguard/README.md | 10 +++++----- .github/chainguard/export-wolfi-export.sts.yaml | 8 ++++---- .github/chainguard/export-wolfi-publish-read.sts.yaml | 8 ++++---- 3 files changed, 13 insertions(+), 13 deletions(-) diff --git a/.github/chainguard/README.md b/.github/chainguard/README.md index 9e5cfd3..58b406a 100644 --- a/.github/chainguard/README.md +++ b/.github/chainguard/README.md @@ -5,11 +5,11 @@ Export writes only wolfi-staging; publication reads only wolfi-staging. These policies are part of [OS-2867](https://linear.app/chainguard/issue/OS-2867). Follow the [production runbook](https://github.com/chainguard-dev/mono/blob/main/env/enforce.dev/iac/400-export-wolfi/README.md). -Merge after staging memory acceptance and paused production infrastructure -provisioning. Replace each `UNPROVISIONED-...` subject with the created account's -numeric `uniqueId` from the stage's `octosts_policies` output; re-run policy checks -and obtain review before merge. The placeholder deliberately matches no Google -service account and must never be treated as a working runtime grant. +Merge after staging memory acceptance and confirmed paused production +infrastructure deployment. These policies bind dedicated production service +accounts by their numeric `uniqueId`. Reconfirm the subjects against the stage's +`octosts_policies` output and obtain review before merge. If an account is +recreated, update its exact subject and repeat the policy checks and review. The three runtime-policy PRs can merge in parallel once their exact subjects are reviewed. Keep both new schedules paused while installing grants. Complete the diff --git a/.github/chainguard/export-wolfi-export.sts.yaml b/.github/chainguard/export-wolfi-export.sts.yaml index 56d4dd5..a30f50b 100644 --- a/.github/chainguard/export-wolfi-export.sts.yaml +++ b/.github/chainguard/export-wolfi-export.sts.yaml @@ -1,8 +1,8 @@ -# Production OS-2867: replace this nonmatching subject after paused provisioning. -# Do not merge until the account's numeric uniqueId has been verified and reviewed. -# Expected account: export-wolfi@prod-enforce-fabc.iam.gserviceaccount.com +# Production OS-2867: bind the dedicated account by its numeric uniqueId. +# Re-review this subject if the service account is recreated. +# Google service account: export-wolfi@prod-enforce-fabc.iam.gserviceaccount.com issuer: https://accounts.google.com -subject: "UNPROVISIONED-export-wolfi-prod-OS-2867" +subject: "100496071258544612791" repositories: - wolfi-staging permissions: diff --git a/.github/chainguard/export-wolfi-publish-read.sts.yaml b/.github/chainguard/export-wolfi-publish-read.sts.yaml index d1dd298..b74b975 100644 --- a/.github/chainguard/export-wolfi-publish-read.sts.yaml +++ b/.github/chainguard/export-wolfi-publish-read.sts.yaml @@ -1,8 +1,8 @@ -# Production OS-2867: replace this nonmatching subject after paused provisioning. -# Do not merge until the account's numeric uniqueId has been verified and reviewed. -# Expected account: export-wolfi-publish@prod-enforce-fabc.iam.gserviceaccount.com +# Production OS-2867: bind the dedicated account by its numeric uniqueId. +# Re-review this subject if the service account is recreated. +# Google service account: export-wolfi-publish@prod-enforce-fabc.iam.gserviceaccount.com issuer: https://accounts.google.com -subject: "UNPROVISIONED-export-wolfi-publish-prod-OS-2867" +subject: "111686246305885758377" repositories: - wolfi-staging permissions: