From 38c678526986f1912d5714079c365d688d9cd351 Mon Sep 17 00:00:00 2001 From: juvdiaz Date: Thu, 4 Jun 2026 18:05:33 -0600 Subject: [PATCH] Persist Cosign signing state outside repo --- README.md | 23 +++++++++++++---------- lab.sh | 7 ++++--- 2 files changed, 17 insertions(+), 13 deletions(-) diff --git a/README.md b/README.md index be90aa8..87c4290 100644 --- a/README.md +++ b/README.md @@ -342,19 +342,22 @@ and audits whether the image has both: - a valid Cosign signature from the homelab signing key - a signed SPDX SBOM attestation -The private Cosign key, generated password, downloaded Cosign binary, and image -state files live under `.lab/`, which is ignored by Git. `./lab.sh apps` creates -or reuses `.lab/cosign.key`, publishes `.lab/cosign.pub` into the Kyverno -namespace as `homelab-cosign-public-key`, builds images with BuildKit SBOM -attestations, signs the pushed images, attaches a signed SPDX SBOM predicate, and -verifies both artifacts before refreshing the workload Applications. The policy -starts in `Audit` mode so an existing live deployment can recover while the -current images are signed; after `./lab.sh apps` verifies both images, change -`validationActions` in +The private Cosign key, generated password, and downloaded Cosign binary live in +`${XDG_DATA_HOME:-$HOME/.local/share}/homelab/` by default so the signing +identity survives temporary checkout cleanup. Repo-local image state files still +live under `.lab/`, which is ignored by Git. `./lab.sh apps` creates or reuses +the persistent Cosign key, publishes the public key into the Kyverno namespace as +`homelab-cosign-public-key`, builds images with BuildKit SBOM attestations, signs +the pushed images, attaches a signed SPDX SBOM predicate, and verifies both +artifacts before refreshing the workload Applications. The policy starts in +`Audit` mode so an existing live deployment can recover while the current images +are signed; after `./lab.sh apps` verifies both images, change `validationActions` in `apps/supply-chain-policy/local-registry-image-policy.yaml` from `Audit` to `Deny` to make it admission-enforcing. Set `COSIGN_PASSWORD` if you want to manage the key password externally; otherwise the Debian runner creates -`.lab/cosign.password` for non-interactive runs. +`cosign/cosign.password` under the homelab state directory for non-interactive +runs. Set `COSIGN_KEY_PREFIX`, `COSIGN_PASSWORD_FILE`, or `COSIGN_BIN` to override +those paths. ## DNS Cache diff --git a/lab.sh b/lab.sh index 3e524fa..88b0831 100755 --- a/lab.sh +++ b/lab.sh @@ -4,10 +4,11 @@ set -euo pipefail REPO_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" BUILDX_CONFIG="/tmp/buildx-config.toml" KUBECONFIG_PATH="${KUBECONFIG_PATH:-${TF_VAR_kubeconfig_path:-/home/jv/.kube/config}}" -COSIGN_KEY_PREFIX="${COSIGN_KEY_PREFIX:-${REPO_ROOT}/.lab/cosign}" +HOMELAB_STATE_DIR="${HOMELAB_STATE_DIR:-${XDG_DATA_HOME:-${HOME}/.local/share}/homelab}" +COSIGN_KEY_PREFIX="${COSIGN_KEY_PREFIX:-${HOMELAB_STATE_DIR}/cosign/cosign}" COSIGN_KEY_PATH="${COSIGN_KEY_PATH:-${COSIGN_KEY_PREFIX}.key}" COSIGN_PUBLIC_KEY_PATH="${COSIGN_PUBLIC_KEY_PATH:-${COSIGN_KEY_PREFIX}.pub}" -COSIGN_PASSWORD_FILE="${COSIGN_PASSWORD_FILE:-${REPO_ROOT}/.lab/cosign.password}" +COSIGN_PASSWORD_FILE="${COSIGN_PASSWORD_FILE:-${HOMELAB_STATE_DIR}/cosign/cosign.password}" COSIGN_VERSION="${COSIGN_VERSION:-2.6.3}" COSIGN_BIN="${COSIGN_BIN:-}" HOMELAB_COSIGN_PUBLIC_KEY_CONFIGMAP="${HOMELAB_COSIGN_PUBLIC_KEY_CONFIGMAP:-homelab-cosign-public-key}" @@ -1662,7 +1663,7 @@ ensure_cosign_available() { ;; esac - target_dir="${REPO_ROOT}/.lab/bin" + target_dir="${HOMELAB_STATE_DIR}/bin" target_path="${target_dir}/cosign-v${COSIGN_VERSION}-linux-${arch}" if [[ -x "${target_path}" ]]; then COSIGN_BIN="${target_path}"