diff --git a/.github/chainguard/README.md b/.github/chainguard/README.md new file mode 100644 index 0000000..b165fc1 --- /dev/null +++ b/.github/chainguard/README.md @@ -0,0 +1,17 @@ +# Production export-wolfi trust + +Publication writes only wolfi-dev/os; the export identity has no public-write grant. + +These policies are part of [OS-2867](https://linear.app/chainguard/issue/OS-2867). +Follow the [production runbook](https://github.com/chainguard-dev/mono/blob/main/env/enforce.dev/iac/400-export-wolfi/README.md). + +Merge after staging memory acceptance and confirmed paused production +infrastructure deployment. These policies bind dedicated production service +accounts by their numeric `uniqueId`. Reconfirm the subjects against the stage's +`octosts_policies` output and obtain review before merge. If an account is +recreated, update its exact subject and repeat the policy checks and review. + +The three runtime-policy PRs can merge in parallel once their exact subjects are +reviewed. Keep both new schedules paused while installing grants. Complete the +single-writer handover and signed-history proof before merging activation. Runtime +accounts have no git-export access; mono's existing build policy handles direct ko. diff --git a/.github/chainguard/export-wolfi-publish.sts.yaml b/.github/chainguard/export-wolfi-publish.sts.yaml new file mode 100644 index 0000000..a715ba8 --- /dev/null +++ b/.github/chainguard/export-wolfi-publish.sts.yaml @@ -0,0 +1,9 @@ +# Production OS-2867: bind the dedicated account by its numeric uniqueId. +# Re-review this subject if the service account is recreated. +# Google service account: export-wolfi-publish@prod-enforce-fabc.iam.gserviceaccount.com +issuer: https://accounts.google.com +subject: "111686246305885758377" +repositories: + - os +permissions: + contents: write