From 025d79359338d86fc408fd3052d7e21375e746f8 Mon Sep 17 00:00:00 2001 From: Joe Borg Date: Mon, 28 Sep 2026 12:50:46 -0400 Subject: [PATCH 1/2] chore(auth): prepare production Wolfi publication grant --- .github/chainguard/README.md | 17 +++++++++++++++++ .../chainguard/export-wolfi-publish.sts.yaml | 9 +++++++++ 2 files changed, 26 insertions(+) create mode 100644 .github/chainguard/README.md create mode 100644 .github/chainguard/export-wolfi-publish.sts.yaml diff --git a/.github/chainguard/README.md b/.github/chainguard/README.md new file mode 100644 index 0000000..e2c1125 --- /dev/null +++ b/.github/chainguard/README.md @@ -0,0 +1,17 @@ +# Production export-wolfi trust + +Publication writes only wolfi-dev/os; the export identity has no public-write grant. + +These policies are part of [OS-2867](https://linear.app/chainguard/issue/OS-2867). +Follow the [production runbook](https://github.com/chainguard-dev/mono/blob/main/env/enforce.dev/iac/400-export-wolfi/README.md). + +Merge after staging memory acceptance and paused production infrastructure +provisioning. Replace each `UNPROVISIONED-...` subject with the created account's +numeric `uniqueId` from the stage's `octosts_policies` output; re-run policy checks +and obtain review before merge. The placeholder deliberately matches no Google +service account and must never be treated as a working runtime grant. + +The three runtime-policy PRs can merge in parallel once their exact subjects are +reviewed. Keep both new schedules paused while installing grants. Complete the +single-writer handover and signed-history proof before merging activation. Runtime +accounts have no git-export access; mono's existing build policy handles direct ko. diff --git a/.github/chainguard/export-wolfi-publish.sts.yaml b/.github/chainguard/export-wolfi-publish.sts.yaml new file mode 100644 index 0000000..f0ddec4 --- /dev/null +++ b/.github/chainguard/export-wolfi-publish.sts.yaml @@ -0,0 +1,9 @@ +# Production OS-2867: replace this nonmatching subject after paused provisioning. +# Do not merge until the account's numeric uniqueId has been verified and reviewed. +# Expected account: export-wolfi-publish@prod-enforce-fabc.iam.gserviceaccount.com +issuer: https://accounts.google.com +subject: "UNPROVISIONED-export-wolfi-publish-prod-OS-2867" +repositories: + - os +permissions: + contents: write From 2fcb903037b7623d80f2a611d4d4dad29d179263 Mon Sep 17 00:00:00 2001 From: Joe Borg Date: Tue, 29 Sep 2026 09:07:21 -0400 Subject: [PATCH 2/2] chore(auth): bind provisioned production Wolfi identities --- .github/chainguard/README.md | 10 +++++----- .github/chainguard/export-wolfi-publish.sts.yaml | 8 ++++---- 2 files changed, 9 insertions(+), 9 deletions(-) diff --git a/.github/chainguard/README.md b/.github/chainguard/README.md index e2c1125..b165fc1 100644 --- a/.github/chainguard/README.md +++ b/.github/chainguard/README.md @@ -5,11 +5,11 @@ Publication writes only wolfi-dev/os; the export identity has no public-write gr These policies are part of [OS-2867](https://linear.app/chainguard/issue/OS-2867). Follow the [production runbook](https://github.com/chainguard-dev/mono/blob/main/env/enforce.dev/iac/400-export-wolfi/README.md). -Merge after staging memory acceptance and paused production infrastructure -provisioning. Replace each `UNPROVISIONED-...` subject with the created account's -numeric `uniqueId` from the stage's `octosts_policies` output; re-run policy checks -and obtain review before merge. The placeholder deliberately matches no Google -service account and must never be treated as a working runtime grant. +Merge after staging memory acceptance and confirmed paused production +infrastructure deployment. These policies bind dedicated production service +accounts by their numeric `uniqueId`. Reconfirm the subjects against the stage's +`octosts_policies` output and obtain review before merge. If an account is +recreated, update its exact subject and repeat the policy checks and review. The three runtime-policy PRs can merge in parallel once their exact subjects are reviewed. Keep both new schedules paused while installing grants. Complete the diff --git a/.github/chainguard/export-wolfi-publish.sts.yaml b/.github/chainguard/export-wolfi-publish.sts.yaml index f0ddec4..a715ba8 100644 --- a/.github/chainguard/export-wolfi-publish.sts.yaml +++ b/.github/chainguard/export-wolfi-publish.sts.yaml @@ -1,8 +1,8 @@ -# Production OS-2867: replace this nonmatching subject after paused provisioning. -# Do not merge until the account's numeric uniqueId has been verified and reviewed. -# Expected account: export-wolfi-publish@prod-enforce-fabc.iam.gserviceaccount.com +# Production OS-2867: bind the dedicated account by its numeric uniqueId. +# Re-review this subject if the service account is recreated. +# Google service account: export-wolfi-publish@prod-enforce-fabc.iam.gserviceaccount.com issuer: https://accounts.google.com -subject: "UNPROVISIONED-export-wolfi-publish-prod-OS-2867" +subject: "111686246305885758377" repositories: - os permissions: