Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
24 changes: 21 additions & 3 deletions content/en/docs/faq.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,9 +66,27 @@ and the interface is described in `docs/DBUS.md` of the repository.

## Are the images signed?

Every blob is verified against the sha256 digest in the image manifest while
it downloads, and registries are reached over HTTPS only. Signatures of
manifests are not verified in this version.
Yes. The workflow that builds the images of the hub, in
[nspawn/mkosi-definitions](https://github.com/nspawn/mkosi-definitions), signs
each one twice with [cosign](https://github.com/sigstore/cosign) after pushing
it: keyless, with the identity of that workflow on `master` (a short-lived
certificate from Fulcio, recorded in the Rekor transparency log), and with the
project's key, whose public half is `cosign.pub` in that repository. The
signatures are stored on the hub next to the image, as OCI referrers of its
digest, so they cover every tag that points to it, and the hub verifies the
key one itself and shows the image as signed. To verify an image yourself:

```shell
cosign verify \
--certificate-identity https://github.com/nspawn/mkosi-definitions/.github/workflows/mkosi.yml@refs/heads/master \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
hub.nspawn.org/fedora:44
```

or, with the key from the repository, `cosign verify --key cosign.pub
hub.nspawn.org/fedora:44`. Every blob is also checked against the sha256
digest in the manifest while it downloads, and registries are reached over
HTTPS only.

## What happened to the wrapper script and the tar images?

Expand Down
7 changes: 4 additions & 3 deletions content/en/docs/overview.md
Original file line number Diff line number Diff line change
Expand Up @@ -149,6 +149,7 @@ configured by systemd-networkd. See [Networking](/docs/networking/).
beyond the names on the bridge, no scheduling.
- It does not build images by itself: `build` needs
[mkosi](https://github.com/systemd/mkosi) installed on the host.
- It does not sign or verify signatures of images. Every blob is checked against
the sha256 digest in the manifest while it downloads, and registries are
reached over HTTPS only.
- It does not sign images: the hub's are signed by the workflow that builds
them (see the [FAQ](/docs/faq/#are-the-images-signed)). Every blob is
checked against the sha256 digest in the manifest while it downloads, and
registries are reached over HTTPS only.