-
Notifications
You must be signed in to change notification settings - Fork 62
Closed
Labels
blockedcomponent:signingCore signing functionalityCore signing functionalityenhancementNew feature or requestNew feature or request
Description
Cosign supports 'ambient credential detection' for a number of environments where OIDC identities are available by default. We should also similarly support:
- GitHub Actions (internal/oidc, test: ambient credentials, refactoring #59)
- Google Cloud: VMs, GKE clusters, Cloud Build, etc. (Google Cloud ambient credential detection #88, Support Google Cloud impersonation #91)
- GitLab (SaaS): https://docs.gitlab.com/ee/integration/openid_connect_provider.html
- CircleCI: https://circleci.com/docs/2.0/openid-connect-tokens/
- BuildKite (oidc: Buildkite support #499)
See also https://dlorenc.medium.com/a-bit-of-ambiance-comes-to-sigstore-f80d1d6b1c30
This issue is tracking support for SaaS products and not self-hosted instances, e.g. GitLab's hosted product and not their on-premise or self-hosted services. Self-hosted services are out-of-scope, pending further discussion with Fulcio.
woodruffw and tetsuo-cpp
Metadata
Metadata
Assignees
Labels
blockedcomponent:signingCore signing functionalityCore signing functionalityenhancementNew feature or requestNew feature or request