From e7fa51560748e41802fb742683d4e9b70d492b1b Mon Sep 17 00:00:00 2001 From: Eduard Tolosa Date: Sat, 26 Sep 2026 05:51:54 -0500 Subject: [PATCH] The images are signed: say so in the FAQ and the overview, with how to verify one --- content/en/docs/faq.md | 24 +++++++++++++++++++++--- content/en/docs/overview.md | 7 ++++--- 2 files changed, 25 insertions(+), 6 deletions(-) diff --git a/content/en/docs/faq.md b/content/en/docs/faq.md index ca4a2ad..2c0a0ed 100644 --- a/content/en/docs/faq.md +++ b/content/en/docs/faq.md @@ -66,9 +66,27 @@ and the interface is described in `docs/DBUS.md` of the repository. ## Are the images signed? -Every blob is verified against the sha256 digest in the image manifest while -it downloads, and registries are reached over HTTPS only. Signatures of -manifests are not verified in this version. +Yes. The workflow that builds the images of the hub, in +[nspawn/mkosi-definitions](https://github.com/nspawn/mkosi-definitions), signs +each one twice with [cosign](https://github.com/sigstore/cosign) after pushing +it: keyless, with the identity of that workflow on `master` (a short-lived +certificate from Fulcio, recorded in the Rekor transparency log), and with the +project's key, whose public half is `cosign.pub` in that repository. The +signatures are stored on the hub next to the image, as OCI referrers of its +digest, so they cover every tag that points to it, and the hub verifies the +key one itself and shows the image as signed. To verify an image yourself: + +```shell +cosign verify \ + --certificate-identity https://github.com/nspawn/mkosi-definitions/.github/workflows/mkosi.yml@refs/heads/master \ + --certificate-oidc-issuer https://token.actions.githubusercontent.com \ + hub.nspawn.org/fedora:44 +``` + +or, with the key from the repository, `cosign verify --key cosign.pub +hub.nspawn.org/fedora:44`. Every blob is also checked against the sha256 +digest in the manifest while it downloads, and registries are reached over +HTTPS only. ## What happened to the wrapper script and the tar images? diff --git a/content/en/docs/overview.md b/content/en/docs/overview.md index b0acac0..81f28d3 100644 --- a/content/en/docs/overview.md +++ b/content/en/docs/overview.md @@ -149,6 +149,7 @@ configured by systemd-networkd. See [Networking](/docs/networking/). beyond the names on the bridge, no scheduling. - It does not build images by itself: `build` needs [mkosi](https://github.com/systemd/mkosi) installed on the host. -- It does not sign or verify signatures of images. Every blob is checked against - the sha256 digest in the manifest while it downloads, and registries are - reached over HTTPS only. +- It does not sign images: the hub's are signed by the workflow that builds + them (see the [FAQ](/docs/faq/#are-the-images-signed)). Every blob is + checked against the sha256 digest in the manifest while it downloads, and + registries are reached over HTTPS only.