Files
Packer-Cn/examples/ci
Tanmay Jain 014f8d1bbe FEAT(provenance): Add SLSA provenance attestation and verification (#13667)
* feat(provenance): add SLSA provenance and attestation signing libraries

Add internal/provenance for deriving in-toto subjects from Packer
artifacts, building SLSA Provenance v1 predicates, wrapping in-toto
statements, and best-effort git/CI source detection.

Add internal/attestation for DSSE envelope handling and a pluggable
Signer/Verifier backend supporting key (local PEM), kms (aws/gcp/
azure/hashivault), and keyless (Sigstore Fulcio) modes, plus Sigstore
bundle handling and DSSE/policy verification.

Add the supporting module dependencies in go.mod/go.sum.

* feat(provenance): add provenance post-processor

Add the opt-in "provenance" post-processor that runs after a build,
derives subjects from the artifact, emits DSSE-wrapped SLSA provenance
(and optional SBOM) attestations, signs them via the configured
signing backend, and writes sidecar files (including *.sigstore.json
bundles in keyless mode). Register it in the core post-processor set.

The provenance enable flag is a tri-state so an unset value stays
enabled through HCL2 decoding instead of being silently disabled.

* feat(provenance): add verify-attestation command

Add "packer verify-attestation" to verify signed DSSE attestations
against key, KMS, and keyless policy inputs, including optional
Sigstore bundle checks for Rekor and timestamp evidence. Register the
command in the CLI.

* docs(provenance): add reference CI workflows and changelog

Add reference GitHub Actions workflows under examples/ci for SLSA L2
keyless signing and L3-compatible delegated signing

* fix: lint and tests

* Added docs for Provenance PostProcessor
2026-07-21 13:40:42 +05:30
..

Provenance CI reference workflows

These are copy-paste reference workflows for producing SLSA provenance with the Packer provenance post-processor. They are not wired into this repository's own CI — copy them into your project's .github/workflows/ directory and adapt the template and artifact paths.

SLSA levels and Packer

SLSA Build levels are mostly properties of the build platform, not the build tool. Packer is a tool, so its reach is:

SLSA Build level Requirement Packer's role What Packer provides
L1 Provenance exists and is distributed Fully in Packer Provenance generation
L2 Provenance signed by a hosted platform Packer signs via CI OIDC identity Keyless signing in CI
L3 Hardened platform; build steps cannot reach the signing key Platform property; Packer is compatible Delegated-signing pattern
L4 Not defined in SLSA v1.0

Packer generates SLSA Provenance v1 and reaches Build L1, and L2 when run on a hosted CI with keyless signing. L3 is a property of the build platform: it requires the signing key to be unreachable by the build steps. Packer does not confer L3 on its own, but the delegated-signing pattern below is compatible with an L3 platform.

Workflows

  • github-actions-l2-keyless.yml — L2: Packer signs provenance keyless using the workflow's OIDC identity, uploads to Rekor, and verifies the signed attestation with packer verify-attestation.
  • github-actions-l3-delegated.yml — L3-compatible: the build job only builds and publishes a digest; provenance generation and signing are delegated to an isolated reusable workflow so the build steps cannot reach the signing material.