mirror of
https://github.com/hashicorp/packer.git
synced 2026-09-28 02:34:02 -04:00
* feat(provenance): add SLSA provenance and attestation signing libraries Add internal/provenance for deriving in-toto subjects from Packer artifacts, building SLSA Provenance v1 predicates, wrapping in-toto statements, and best-effort git/CI source detection. Add internal/attestation for DSSE envelope handling and a pluggable Signer/Verifier backend supporting key (local PEM), kms (aws/gcp/ azure/hashivault), and keyless (Sigstore Fulcio) modes, plus Sigstore bundle handling and DSSE/policy verification. Add the supporting module dependencies in go.mod/go.sum. * feat(provenance): add provenance post-processor Add the opt-in "provenance" post-processor that runs after a build, derives subjects from the artifact, emits DSSE-wrapped SLSA provenance (and optional SBOM) attestations, signs them via the configured signing backend, and writes sidecar files (including *.sigstore.json bundles in keyless mode). Register it in the core post-processor set. The provenance enable flag is a tri-state so an unset value stays enabled through HCL2 decoding instead of being silently disabled. * feat(provenance): add verify-attestation command Add "packer verify-attestation" to verify signed DSSE attestations against key, KMS, and keyless policy inputs, including optional Sigstore bundle checks for Rekor and timestamp evidence. Register the command in the CLI. * docs(provenance): add reference CI workflows and changelog Add reference GitHub Actions workflows under examples/ci for SLSA L2 keyless signing and L3-compatible delegated signing * fix: lint and tests * Added docs for Provenance PostProcessor
65 lines
2.0 KiB
YAML
65 lines
2.0 KiB
YAML
# Reference workflow — NOT wired into this repository's CI.
|
|
#
|
|
# Copy this into your own project's .github/workflows/ directory.
|
|
#
|
|
# SLSA Build L3-compatible pattern: the build job ONLY builds the artifact and
|
|
# publishes its digest. Provenance generation and signing are delegated to an
|
|
# isolated, reusable workflow (the SLSA GitHub generator) that runs in a
|
|
# separate job the build steps cannot influence or reach. This keeps the
|
|
# signing material unreachable from the build, which is what L3 requires.
|
|
#
|
|
# Packer itself does not confer L3. It participates by producing the artifact;
|
|
# the platform (isolated signer) provides the L3 property.
|
|
|
|
name: build-and-delegate-provenance
|
|
|
|
on:
|
|
push:
|
|
tags:
|
|
- "v*"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
build:
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
digest: ${{ steps.hash.outputs.digest }}
|
|
steps:
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
|
|
- name: Install Packer
|
|
uses: hashicorp/setup-packer@main
|
|
with:
|
|
version: latest
|
|
|
|
- name: Initialize plugins
|
|
run: packer init .
|
|
|
|
# Build only. Do NOT sign here: signing in the build job would defeat the
|
|
# isolation that the delegated signer provides.
|
|
- name: Build artifact
|
|
run: packer build .
|
|
|
|
# Emit a base64-encoded subject digest for the delegated generator.
|
|
- name: Compute artifact digest
|
|
id: hash
|
|
run: |
|
|
# Adjust the artifact path to match your build output.
|
|
echo "digest=$(sha256sum output/image.qcow2 | base64 -w0)" >> "${GITHUB_OUTPUT}"
|
|
|
|
# Isolated, reusable workflow that generates and signs SLSA provenance in a
|
|
# job the build cannot reach. This is the component that provides the L3
|
|
# property; pin it to a released tag in real usage.
|
|
provenance:
|
|
needs: [build]
|
|
permissions:
|
|
actions: read
|
|
id-token: write
|
|
contents: write
|
|
uses: slsa-framework/slsa-github-generator/.github/workflows/[email protected]
|
|
with:
|
|
base64-subjects: ${{ needs.build.outputs.digest }}
|