Skip to content

build/bake,build: add Chainguard OIDC keyless cgr.dev auth (opt-in)#196

Open
danilohorta wants to merge 3 commits into
docker:mainfrom
danilohorta:feat/chainguard-keyless-auth
Open

build/bake,build: add Chainguard OIDC keyless cgr.dev auth (opt-in)#196
danilohorta wants to merge 3 commits into
docker:mainfrom
danilohorta:feat/chainguard-keyless-auth

Conversation

@danilohorta
Copy link
Copy Markdown

@danilohorta danilohorta commented May 11, 2026

Summary

bake.yml and build.yml currently only accept registry credentials via the static registry-auths secret, so any runtime-minted credential (Chainguard OIDC pull token, GCP WIF, AWS OIDC, …) has to be substituted across the workflow_call boundary, where GitHub's cross-job output masker silently strips values that look like secrets.

This PR adds three opt-in inputs (chainguard-identity, chainguard-apk-host, chainguard-libraries-host) that drive chainguard-dev/setup-chainctl@v0.5.1 inside the build and finalize jobs so the Chainguard pull token is minted on the build runner and never leaves it.

Issue: #146

Add four opt-in inputs to bake.yml and build.yml:
chainguard-identity, chainguard-registry, chainguard-apk-host,
chainguard-libraries-host. When chainguard-identity is set, the
build and finalize jobs install chainctl via
chainguard-dev/setup-chainctl@v0.5.1 and register it as a Docker
credential helper for cgr.dev. The Chainguard pull token is minted
inside the build/finalize job runners and never crosses the
workflow_call boundary into the caller's registry-auths secret,
where it would be silently stripped by GitHub's cross-job output
masker (docker#146 documents the equivalent GCP WIF failure mode).

No existing input changes; registry-auths continues to handle every
static-credential registry as before and can be combined with
chainguard-identity for multi-registry builds.

Refs: docker#146
@danilohorta danilohorta requested a review from a team as a code owner May 11, 2026 14:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants