Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions .github/chainguard/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
# Production export-wolfi trust

Publication writes only wolfi-dev/os; the export identity has no public-write grant.

These policies are part of [OS-2867](https://linear.app/chainguard/issue/OS-2867).
Follow the [production runbook](https://github.com/chainguard-dev/mono/blob/main/env/enforce.dev/iac/400-export-wolfi/README.md).

Merge after staging memory acceptance and confirmed paused production
infrastructure deployment. These policies bind dedicated production service
accounts by their numeric `uniqueId`. Reconfirm the subjects against the stage's
`octosts_policies` output and obtain review before merge. If an account is
recreated, update its exact subject and repeat the policy checks and review.

The three runtime-policy PRs can merge in parallel once their exact subjects are
reviewed. Keep both new schedules paused while installing grants. Complete the
single-writer handover and signed-history proof before merging activation. Runtime
accounts have no git-export access; mono's existing build policy handles direct ko.
9 changes: 9 additions & 0 deletions .github/chainguard/export-wolfi-publish.sts.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
# Production OS-2867: bind the dedicated account by its numeric uniqueId.
# Re-review this subject if the service account is recreated.
# Google service account: export-wolfi-publish@prod-enforce-fabc.iam.gserviceaccount.com
issuer: https://accounts.google.com
subject: "111686246305885758377"
repositories:
- os
permissions:
contents: write
Loading