Skip to content

Add sigstore verification for registry.access.redhat.com#1226

Closed
wshanks wants to merge 1 commit intoublue-os:mainfrom
wshanks:patch-1
Closed

Add sigstore verification for registry.access.redhat.com#1226
wshanks wants to merge 1 commit intoublue-os:mainfrom
wshanks:patch-1

Conversation

@wshanks
Copy link
Copy Markdown

@wshanks wshanks commented Apr 13, 2026

Bluefin LTS uses a CentOS base that does not include the gpg key for registry.access.redhat.com. It does have the sigstore key though. Here the sigstore method is added to policy.json. This addition avoids signature verification failure when trying to pull images from registry.access.redhat.com (like the ubi images) with podman on Bluefin LTS.

See ublue-os/bluefin-lts#1292 for more context.

Bluefin LTS uses a CentOS base that does not include the gpg key for registry.access.redhat.com. It does have the sigstore key though. Here the sigstore method is added to policy.json. This addition avoids signature verification failure when trying to pull images from registry.access.redhat.com (like the ubi images) with podman on Bluefin LTS.

See ublue-os/bluefin-lts#1292 for more context.
@codacy-production
Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

TIP This summary will be updated as you push new changes. Give us feedback

@renner0e
Copy link
Copy Markdown
Member

This is not used anymore by bluefin.
You will want to make a PR to https://github.com/projectbluefin/common

@wshanks
Copy link
Copy Markdown
Author

wshanks commented Apr 14, 2026

Thanks, I moved the change to projectbluefin/common#276.

@wshanks wshanks closed this Apr 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants