build(release): build the container image with melange + apko - #43
Merged
Merged
Conversation
Replace the multi-stage Dockerfile + docker buildx image build with melange (signed Wolfi apk of the controller-manager) + apko (minimal multi-arch nonroot OCI image), mirroring the former gcr.io/distroless/static:nonroot posture (uid 65532, ca-certs, tzdata, no shell, /usr/bin/manager entrypoint). Per-arch apks build on native runners (amd64 + arm64), so multi-arch no longer needs QEMU. Faithful to the supply-chain upgrade: add keyless cosign signing and a syft Go-module-granularity image SBOM attestation. The existing SLSA provenance attestation (actions/attest, the one the optional Kyverno policy verifies) stays inline and release.yml-signed, so the chart's Kyverno defaults (buildType + release.yml signer identity) are unchanged here — moving provenance into an isolated reusable workflow (SLSA L3) is a follow-up. - melange.yaml / apko.yaml (new): signed apk + minimal image; versions bumped by release-please (extra-files). - release.yml / release-dry-run.yml / security-scan.yml: melange + apko replace buildx. The multi-arch index digest that cosign/SBOM/provenance bind to is resolved authoritatively from the registry (docker buildx imagetools inspect), not parsed from apko stdout; mkdir -p sbom before publish. - dev/image-build.sh (new) + scripts/test-e2e.sh: the Kind e2e builds the same apko image locally (the dev Tilt/ko loop is unchanged). - Delete Dockerfile + .dockerignore; gitignore the local melange/apko artifacts. Verified: local melange+apko build runs the manager (--help, exit 0) as uid 65532 with /usr/bin/manager entrypoint and no shell; root:check green; chart still renders the Kyverno policy trusting release.yml; the published v0.1.2 attestation confirms actions/attest emits slsa.dev/provenance/v1 + buildtypes/workflow/v1, the exact contract the Kyverno policy checks. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Replaces the multi-stage
Dockerfile+docker buildximage build withmelange (signed Wolfi apk of the controller-manager) + apko (minimal
multi-arch nonroot OCI image), and adds keyless cosign signing + a syft
image SBOM attestation. This is PR2 of the template-go-api session-015
reproduction (mise → melange/apko → SLSA L3 reusable
attest.yml→skills/docs).
melange.yaml/apko.yaml(new): the apk mirrors the former Dockerfile(
go build ./cmd→/usr/bin/manager); the image mirrorsdistroless/static:nonroot(uid 65532, ca-certs, tzdata, no shell). Versionsare bumped by release-please (
extra-files).release.yml/release-dry-run.yml/security-scan.yml: per-arch apksbuild on native runners (no QEMU); apko assembles + publishes the
multi-arch index. The index digest that cosign/SBOM/provenance bind to is
resolved authoritatively from the registry (
imagetools inspect).dev/image-build.sh(new) +scripts/test-e2e.sh: the Kind e2e builds thesame apko image locally (the
ko/Tilt dev loop is unchanged).Dockerfile+.dockerignore; gitignore the local melange/apkoartifacts.
Supply-chain contract preserved
The chart's optional Kyverno policy verifies the image's SLSA provenance
(
slsa.dev/provenance/v1, buildType…/buildtypes/workflow/v1, signerrelease.yml@<tag>). PR2 keeps thatactions/attestprovenance inline andrelease.yml-signed, so the Kyverno defaults are unchanged. Moving
provenance into an isolated reusable workflow (SLSA L3) — and the matching
Kyverno signer flip — is PR3.
Testing
dev/image-build.sh):manager --helpruns(exit 0), User=65532, Entrypoint
/usr/bin/manager, ~51 MB, no shell.helm template --set kyverno.imageVerification.enabled=truestill renders thepolicy trusting
release.yml+buildtypes/workflow/v1.moon run root:checkgreen;git diff --checkclean; no artifact leaks.v0.1.2image attestation confirmsactions/attest@v4.1.0emitsslsa.dev/provenance/v1+buildtypes/workflow/v1— exactly what Kyverno checks.completeness) found one real robustness item (now fixed: authoritative index
digest) and no remaining blockers.
the native multi-arch build + apko assemble on CI.
🤖 Generated with Claude Code