Skip to content

M0.12: enforce verified deployment paths - #15

Merged
pgousdal merged 10 commits into
mainfrom
work/m0.12-deployment-enforcement
Sep 5, 2026
Merged

pgousdal merged 10 commits into
mainfrom
work/m0.12-deployment-enforcement

Conversation

@pgousdal

@pgousdal pgousdal commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Implements M0.12 deployment enforcement on top of M0.11 verification.

Changes:

  • allow compose.yaml to consume an immutable verified image via GLOWING_BEAR_IMAGE;
  • add scripts/deploy-verified-compose.sh, which verifies the release first, pulls only the immutable digest, validates Compose, and starts with --no-build;
  • add scripts/render-verified-quadlet.sh, which emits a Quadlet only after verification and pins Image= to the immutable digest;
  • add Deployment enforcement CI that exercises a real signed release (v0.2.3), verifies the running Compose container uses an immutable digest, checks /healthz, and validates Quadlet output;
  • document the fail-closed operator policy and its scope in docs/M0_12_DEPLOYMENT_ENFORCEMENT.md.

This intentionally does not claim host-wide Docker/Podman admission control; it enforces the repository's supported secure deployment paths.

@pgousdal
pgousdal merged commit b57d0f1 into main Sep 5, 2026
16 checks passed
@pgousdal
pgousdal deleted the work/m0.12-deployment-enforcement branch September 5, 2026 12:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant