Signing event: sign/multi-region#413
Conversation
Add keys and certificates for new services deployed in us-east4. Fulcio and TSA are isolated services operating under the same URL as the existing services in us-central1, so we add their certificates using the same URL. The new rekor-tiles and ctlog-tiles log shards have their own origin names and are treated by verifiers as distinct services. Signed-off-by: Colleen Murphy <colleenmurphy@google.com>
All rekor-tiles shards will be writeable using a single signing address, global.rekor.sigstage.dev. The responses will include the origin name of the server that actually responded, such as log2025-alpha3.rekor.sigstage.dev or log2026-1.us-east4.rekor.sigstage.dev, which verifiers will use to match the response with a key in the trusted root. Also remove the current active shard (log2025-alpha3) since that will be reachable from the global address, and the frozen shards which no one should be writing to anymore. Signed-off-by: Colleen Murphy <colleenmurphy@google.com>
Add keys for services in us-east4
Signed-off-by: TUF-on-CI <41898282+github-actions[bot]@users.noreply.github.com>
Artifacts have been modifiedEvent sign/multi-region (commit d88bca2) |
Current signing event stateEvent sign/multi-region (commit 9758874) ❌ targetsRole
Role |
Add global rekor-tiles address to signing config
Signed-off-by: TUF-on-CI <41898282+github-actions[bot]@users.noreply.github.com>
Artifacts have been modifiedEvent sign/multi-region (commit 8294fa6) |
Current signing event stateEvent sign/multi-region (commit 5330795) ❌ targetsRole
Role |
This comment was marked as outdated.
This comment was marked as outdated.
Signed-off-by: Jussi Kukkonen <jkukkonen@google.com>
Current signing event stateEvent sign/multi-region (commit a78a5b2) ✅ targetsRole
Role Signing event is successfulThreshold of signatures has been reached: this signing event can be reviewed and merged. |
|
For context: this PR contains trust root and signing config changes that enable multi-region sigstore:
|
Signed-off-by: Fredrik Skogman <kommendorkapten@github.com>
Current signing event stateEvent sign/multi-region (commit c2b6557) ✅ targetsRole
Role Signing event is successfulThreshold of signatures has been reached: this signing event can be reviewed and merged. |
Processing signing event sign/multi-region, please wait.