Skip to content

build(release): build the container image with melange + apko - #43

Merged
jmgilman merged 1 commit into
masterfrom
build/melange-apko
Jun 28, 2026
Merged

jmgilman merged 1 commit into
masterfrom
build/melange-apko

Conversation

@jmgilman

Copy link
Copy Markdown
Contributor

Summary

Replaces the multi-stage Dockerfile + docker buildx image build with
melange (signed Wolfi apk of the controller-manager) + apko (minimal
multi-arch nonroot OCI image), and adds keyless cosign signing + a syft
image SBOM attestation
. This is PR2 of the template-go-api session-015
reproduction
(mise → melange/apko → SLSA L3 reusable attest.yml →
skills/docs).

  • melange.yaml / apko.yaml (new): the apk mirrors the former Dockerfile
    (go build ./cmd → /usr/bin/manager); the image mirrors
    distroless/static:nonroot (uid 65532, ca-certs, tzdata, no shell). Versions
    are bumped by release-please (extra-files).
  • release.yml / release-dry-run.yml / security-scan.yml: per-arch apks
    build on native runners (no QEMU); apko assembles + publishes the
    multi-arch index. The index digest that cosign/SBOM/provenance bind to is
    resolved authoritatively from the registry (imagetools inspect).
  • dev/image-build.sh (new) + scripts/test-e2e.sh: the Kind e2e builds the
    same apko image locally (the ko/Tilt dev loop is unchanged).
  • Delete Dockerfile + .dockerignore; gitignore the local melange/apko
    artifacts.

Supply-chain contract preserved

The chart's optional Kyverno policy verifies the image's SLSA provenance
(slsa.dev/provenance/v1, buildType …/buildtypes/workflow/v1, signer
release.yml@<tag>). PR2 keeps that actions/attest provenance inline and
release.yml-signed
, so the Kyverno defaults are unchanged. Moving
provenance into an isolated reusable workflow (SLSA L3) — and the matching
Kyverno signer flip — is PR3.

Testing

  • Local melange + apko build (dev/image-build.sh): manager --help runs
    (exit 0), User=65532, Entrypoint /usr/bin/manager, ~51 MB, no shell.
  • helm template --set kyverno.imageVerification.enabled=true still renders the
    policy trusting release.yml + buildtypes/workflow/v1.
  • moon run root:check green; git diff --check clean; no artifact leaks.
  • Ground-truth check: the published v0.1.2 image attestation confirms
    actions/attest@v4.1.0 emits slsa.dev/provenance/v1 +
    buildtypes/workflow/v1 — exactly what Kyverno checks.
  • A 4-agent adversarial review (release-graph / supply-chain / build /
    completeness) found one real robustness item (now fixed: authoritative index
    digest) and no remaining blockers.
  • The melange/apko release-dry-run is dispatched on this branch to exercise
    the native multi-arch build + apko assemble on CI.

🤖 Generated with Claude Code

Replace the multi-stage Dockerfile + docker buildx image build with melange
(signed Wolfi apk of the controller-manager) + apko (minimal multi-arch nonroot
OCI image), mirroring the former gcr.io/distroless/static:nonroot posture (uid
65532, ca-certs, tzdata, no shell, /usr/bin/manager entrypoint). Per-arch apks
build on native runners (amd64 + arm64), so multi-arch no longer needs QEMU.

Faithful to the supply-chain upgrade: add keyless cosign signing and a syft
Go-module-granularity image SBOM attestation. The existing SLSA provenance
attestation (actions/attest, the one the optional Kyverno policy verifies) stays
inline and release.yml-signed, so the chart's Kyverno defaults
(buildType + release.yml signer identity) are unchanged here — moving provenance
into an isolated reusable workflow (SLSA L3) is a follow-up.

- melange.yaml / apko.yaml (new): signed apk + minimal image; versions bumped by
  release-please (extra-files).
- release.yml / release-dry-run.yml / security-scan.yml: melange + apko replace
  buildx. The multi-arch index digest that cosign/SBOM/provenance bind to is
  resolved authoritatively from the registry (docker buildx imagetools inspect),
  not parsed from apko stdout; mkdir -p sbom before publish.
- dev/image-build.sh (new) + scripts/test-e2e.sh: the Kind e2e builds the same
  apko image locally (the dev Tilt/ko loop is unchanged).
- Delete Dockerfile + .dockerignore; gitignore the local melange/apko artifacts.

Verified: local melange+apko build runs the manager (--help, exit 0) as uid
65532 with /usr/bin/manager entrypoint and no shell; root:check green; chart
still renders the Kyverno policy trusting release.yml; the published v0.1.2
attestation confirms actions/attest emits slsa.dev/provenance/v1 +
buildtypes/workflow/v1, the exact contract the Kyverno policy checks.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@jmgilman
jmgilman merged commit 800bbfb into master Jun 28, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant