From a6fa707ae088aa24d4f6ab30e4dc016d8709ed3d Mon Sep 17 00:00:00 2001 From: Kara Guo Date: Wed, 22 Nov 2023 00:14:34 +0000 Subject: [PATCH] Proposal for harbor cosign signature verification To add a proposal for cosign signature verification in Harbor Signed-off-by: Kara Guo --- .../enable-feature-1.png | Bin 0 -> 22532 bytes .../enable-feature-2.png | Bin 0 -> 29726 bytes .../middlewares.png | Bin 0 -> 28294 bytes .../sequence-diagram.png | Bin 0 -> 28714 bytes .../new/cosign-signature-verification.md | 177 ++++++++++++++++++ 5 files changed, 177 insertions(+) create mode 100644 proposals/images/cosign-signature-verification/enable-feature-1.png create mode 100644 proposals/images/cosign-signature-verification/enable-feature-2.png create mode 100644 proposals/images/cosign-signature-verification/middlewares.png create mode 100644 proposals/images/cosign-signature-verification/sequence-diagram.png create mode 100644 proposals/new/cosign-signature-verification.md diff --git a/proposals/images/cosign-signature-verification/enable-feature-1.png b/proposals/images/cosign-signature-verification/enable-feature-1.png new file mode 100644 index 0000000000000000000000000000000000000000..8d7379717a28af07df0a402a47d4ec7904764044 GIT binary patch literal 22532 zcmeFZ1yI%B*Ef0)1w}%nTLDG7yF^MFr8^FsLwBc&2+|>)0us{QAl;yVbVzr1-+lP~ z^FGhqJI~C0@4WBK|2WP$-&)_j*IsMw6`#dtMR`dKG-5Oe1cD*;TI?+Zawiu8L3(;0 z1)NbITN?ylEpE!{4sQ*dpV-)0!%QuVpE$VM7(X#~F@-@OE)$lDTA0XB?_Zwa3f?Jn zoa3=_PB=sn^m@aRV@ZSE9_RnET6aLQ+VPQexaFu>`3F(ipm-eLmn7IC66k9XX~$m= z4c_keCi9}_huf~7>BB7gD?(qnDJ-aCM0RHA`KD3)nR&Sa$1h=M#YKU=$A^k=P76!& zFsXmFmBvalpAvF-vgPsjkZto+UcB;s zOJBCGZ@1?6Gvle0tu3zhLrgCQRWj{FM@JjHyG>Y+)Cg$A3267crM`*>p>|xkIPch= zU_LT?mKksP=H+h&D!kCoahm~zF5(2|KSNoAWO|3;kzIEMIz|OOJn92?8FuWwL#&>` z*?!PGmW;DfZ{27eN{H@vP2p(`hOVz4*hMAyI3-Cb@gFiW zRI<<$)9vBfs=wjvCSYTtPpst0{f1^f71_uVI}{yLC2xPPsvbA&^*1rI*!6rkPu&os=Wb|pT3#nQscp3g;)@|G?i_>DNtO!?&Y76)@d zN_9EKC!*GN#!onyIG9)%#a&FD*eHe2o(R|(!T8>aN&JljI1;2Zad5EVV`g@Cc4l&B zXR@|~GqdvY@-nlqF|)BTf;$-PU9B7pTo|qFsSqUoq9JB%54AJ3aWJ*EdV-*7U}){= zAV^6Gu0Q$v_$+PYodA))4d}mp!d@Au zDf3%nduvBKsIj<{v6TbWzmhP5{^NNYM>~t#=@>zojV+8V!L9b-t*rm{N=Yd>#eY13 zU;*6J(&qLl!0dm!)4>$>PiFnw*brB4r}M7^0gwNK?!Vpr_qpHR4DOPX;}f%nIwFQA zB_>FTct4+!HPqCI@AfAf7dH!w0Xq*Prva-GBL^3hm(hS7%EicQ%*F=gG~(bfVP$9IG2rE4WrT9WI2bwD*bNzZj9`ESl#R=f1;%9rv8|E=l(hej2Ezl%>OWkf8!a# z?EEkM{B14%7rp_I{?AMPNBsQ{yZ*zj{}BiNM>qdRy8gqi{}BiNM>qdRy8b_77ur9= zDPt?(1v!IY>7Bk*EC{qv3}qz6AUBAAsr6Zr;LHP?*BbT^$U_{&eL4X2 zj=J&?kARhwwDODz0(koDMXy4npV~F&Sj`Da$5!ao0%zft>aj+qG zw7OwTt5qJW6NeM7IQE;())~rTaRz@hr@SYFGs6BPu1$Awa2^Py*b7L);BdHiDgVJ{ zk~+y8B1S+2@1u7X`5jQr^xOZsA~J&J3MNE~CEqBjNJvPphk|CYBP|*x?x@ zZ&9&`x`*HcIYSwoOSwFT(1d&DBwBbYIM@y}?>5w!O5s`jsLng7q8s19E zZyH2=Q1*s?;q|sI9HNJ5!q? zPU2)3#}|x7X*+E8Ge|jy!DO(Ewj+f6sY0^AXD6NCC4g?k$GfPgO4*7A%LNYUsY&%{ zl-?#=`#ZdKaDE|FEJMQx9_Gj2WYj(b20h&vEzI(WT1WdH@noy^=s7h9Iu=%_SZxSe zE+yrD*L^fJ!{6Uks%mPUo6JBvLatV37Bc%1a;CGRxGJdqoAguVVv-rO8ng{m#Kab% zZkMO5$H&L$6hevOf%sQzm*nK+WtNl2!Y4vk1*hSKHg7C#q>AQ^>E_-0xqlU;ps0WL z@1&VqN%3BuYw??E^rkR3-=Mw_^7(M5E5kgy+r6kO(RZ@anie6b9t<(edhJ6)IPb{# zofN+-(+1$tw@1<_>>eJr4h)12=O_(jzoA0Ieer0Aja=BPw?B!$+UVO4z}=IRj=nw&et!PC`uYWdn4if%1o6K%~h8B64ZS0->3tTcJ-dFailWt{xVhXPC!CJ0$Kl^OJJ>! z@$g|wQxg(1Gcy?Ocqtr9US6JupP$`gj0FPgjTQMO9Tha-db<0RRw+~YtN8VEjH1Wb z;R=K0=A+rlIT5Vc=VxcOr@M15sN#LGtUhRXbdMfCe%1Yj)^w_h)pdXIDH~gacD3D` zGLtv3{zOyKH&>^7P*PG-LVl+_G{$}I9AhBLLQ>PU&hYcYH3Wy>0U>+a;NfaDQ%3}! znW=X#HTzA6M!+OnZuYy%Wsg!sM1WHAJbd_Yp#+FXJHoCVZxU5hR1AMt2{h`8xVk`f z@_Ap1G*I5ORL`^cTFx-|BSMuarGR0lE-(5nggBs#Fu7H!zgzqN*681w(o5%$zP_Gs zcTP6m3y!UnC(U^Zr5lLzPmJVt7HlO1he}FHmd+SsTdu37g3~pX1sz>fe%Cf}ekVK2 z2hol}J@#4~h8~-T#VLgRW1r=6V}8|1&=RW^!;dS|A7FXsW2OA{8X_4P88%q&>&WMF z>P7lUSqdrggGk3Qr8IFobrjFKzpNxw_q4baFKapSg?X^s7 zeaTl3o=J+gTRxq0iE&>1LyqETEm=N+p;6ZF!z75xVn2A_OIv{8-JcGuJv-+%&xKIg zoFPbeuVRN8}xTn|^n(e}7w6A}*2kIWeu8D010#Utuy zUq*g!qt$B*e>3ZW`f@B+kq)=apdU?*PT4V|#uF1I*e+8gYrA~~-Em#a?~T_v zq`o)Q(7yBc@8lP7JM;(J(v|ywH{|*A=jxi8hL)Cnz|>W{9>5~5^A@`kW>0SxY2QZl z3h;(wV^2M(>gpk2exY0Ak#{B&mD?H>*w|W|M<3I_pqTk8&-7W3%KTcS{x-@q(i52q z()Ls|#WEM#<`zBsg>^hn+Z%Bh!ZYafR@h(cG9Avw_Cdi&vs>y;X?5q~3>K~slawTC zxtK&JoEg_7B*XJ<()Smi z+zRsB9`}xrE(!il)${z2uGzY`FLJ2H9&1^SOktTpqbsTsf?6-QH&O9@p}XT~5s#$j5x1LZ2T{pJETSdy5BR>J%51 zDgVM#6&Di|^MXSYIOSjWMlkZzzRkR=|HuD9#_PC5z<1f@DE2 zGZzVPxI^#}5&Ej)p}|HRZXwF9_2fcz)SjsO!BAVO!u-{`8Q6iq=T>tmy;D@qgLuB= zXS|}mvyOt0(UX@MRuGE1WN@@2GYtWw78Aq09laQ0BL<(pzW#RZ-@pFr9gB^Y0!0l zWgzP>ho){MUvsX0TE#c)?qq#m6gavyG@ZhQI<-!uH*1ha-CY&dMTIN3rWhPQte*us z{C|6uhK2^KW4CfUhV6XY0i4diZYXeNfRMZObBCh~>rWE1%2Eze?Ax6hxB|EQz`kWP z_TRt$I`{wU9pRO6Id_2!N~MH`VrflR7Eewl_+f3^bH8{kekNwrlk8J>wm+0@AUaWL zE;^E@aig?h?H>{nG6KWJ4i9yD!bbS>>uL%{j*lPuQdjB9u;pO<>>aYP?8UOJTIQ|tV*0ZNld6V%e(EqyDW21g5k80;{Xl|gT=`Dd|`ZQkr%pQhAi zkNIQ)uhwRbSsSAptBPvtwx+MQtoLtTZ?yiCDst&?c$b}^kV@wq9SBEBhdsTL1QzV# z*i!k0o)8d@bA&5N%?kEvm!0u}`C$HH*(8a3;XG!XCKBJ3@i{Cff}oP2VKfTKtrtG3 zj0i9I4VIXh##QPEA0JxfY!-X9nm0fDb?=1>mpPrCkRH#341D#8jiv4n6uZig{{8c( zB0jT5b2Ot?wZ|FT$+nr%SAS|UA~qPc%*dwlclGe&tqH|)GZj4X$MwJ&RBDiRyr&`+ zc0BD?>OT2gKtRA`FhgqoQshESOBIWZPwe8DtcY19~AopNUdRVmIAy zs@gGfsKcvy$dWOK@oh1z&kPNpA$#7V6FFQ{RX97o-0W9fBu|I5a%A^I{R+DIy~8jRrZDmjuU*`kRv`D<5y2*E_50 zR9Fxlf9s~r4(O!G(VT8~skYW1FEKt`8s)N z(?2*^F3q(NC|hi7yji-;hq(ASa1d?+rsC&mIbITV&NyM-0|t_7o4{06U7hpj<|!71 z(Bj}XnU8*c_J4jL0q^TmZZ3Vj`$?w#N`F;t?ZU=J&&jO!!2VJXRM2_8^|Qrf1%^M7 zsa_4J2=&E_D=XuIV03JJd~RbSmoo5Dbf(t$=+gJ0hviOc_h;}Xo8pK>C7v?{TN|5H z;5=(r*}TW2S0&8SYw(E6RV$33lEj2mSd8!c_1HQ&0ZBYuw{Ht^!F$k)ci&R99%rg2Suf&>?prKj+L7e@Y*jMfqbx$HMJJ3671_pG0-mRUT9czy|*MsFe z?dk|H|2vQH@Y+D6C_he49qukbc7^O^8GXGmwyz@f( zPz`x?^4q<_7Tvb^XhygdoocT5)~CLkeLL&fx~7kX=Z3K8AYOVdL#t$gkp&UwI|$d> zg4dqiYU0CPMs_yJ4;x-FU3yg}AC_n9obKsv7wmX=YzN3?$VRPOkJ|ilj+BB~^{;sP zwO&+BY7!LaRJRuGDdE)h7O8!$%C|Sz>9@Q)jrpUQjZ?*JWZ|Gew5Uk-s;S~;h^DE| zV=s|m+|HxOSeNgH-8V4$PbZSKD#PV=(t(D$I-C1hJJxj^CYE