diff --git a/charts/trusted-artifact-signer/Chart.yaml b/charts/trusted-artifact-signer/Chart.yaml index a8b5ac6f..f3452d59 100644 --- a/charts/trusted-artifact-signer/Chart.yaml +++ b/charts/trusted-artifact-signer/Chart.yaml @@ -33,4 +33,4 @@ sources: # This is the chart version. This version number should be incremented each time you make changes # to the chart and its templates, including the app version. # Versions are expected to follow Semantic Versioning (https://semver.org/) -version: 0.1.41 +version: 0.1.42 diff --git a/charts/trusted-artifact-signer/ci/ci-values.yaml b/charts/trusted-artifact-signer/ci/ci-values.yaml index 84cb7d73..63c8c1cb 100644 --- a/charts/trusted-artifact-signer/ci/ci-values.yaml +++ b/charts/trusted-artifact-signer/ci/ci-values.yaml @@ -10,8 +10,14 @@ configs: clientserver: consoleDownload: false route: false + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/access-1-0-gamma/client-server-1-0-gamma cosign_deploy: enabled: true + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/cli-1-0-gamma/cosign-cli-2-2 fulcio: clusterMonitoring: enabled: false @@ -26,8 +32,28 @@ configs: # github.com/sigstore/helm-charts/charts scaffold: + # ctlog: + # server: + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/scaffold-1-0-gamma/ct-server-0-6 + # createctconfig: + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/scaffold-1-0-gamma/createctconfig-0-6 + # createtree: + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/trillian-1-0-gamma/createtree-0-6 fulcio: + # createcerts: + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/fulcio-1-0-gamma/createcerts-1-0-gamma server: + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/fulcio-1-0-gamma/fulcio-1-0-gamma ingress: enabled: false http: @@ -41,11 +67,55 @@ scaffold: ClientID: sigstore Type: email rekor: + # redis: + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/trillian-1-0-gamma/redis-0-6 server: + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/rekor-1-0-gamma/rekor-server-1-0-gamma ingress: enabled: false http: enabled: false + # createtree: + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/trillian-1-0-gamma/createtree-0-6 + # backfillredis: + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/rekor-1-0-gamma/backfill-redis-1-0-gamma + # trillian: + # createdb: + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/trillian-1-0-gamma/createdb-0-6 + # initContainerImage: + # netcat: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/trillian-1-0-gamma/trillian-netcat-1-5 + # redis: + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/trillian-1-0-gamma/redis-0-6 + + # logSigner: + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/trillian-1-0-gamma/trillian-logsigner-1-5 + # logServer: + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/trillian-1-0-gamma/trillian-logserver-1-5 + # mysql: + # image: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/trillian-1-0-gamma/trillian-database-1-5 tuf: ingress: create: false + # deployment: + # registry: quay.io + # repository: redhat-user-workloads/rhtas-tenant/scaffold-1-0-gamma/tuf-server-0-6 diff --git a/charts/trusted-artifact-signer/templates/tests/test-sign-verify.yaml b/charts/trusted-artifact-signer/templates/tests/test-sign-verify.yaml index 0b4a4eff..1fde7a65 100644 --- a/charts/trusted-artifact-signer/templates/tests/test-sign-verify.yaml +++ b/charts/trusted-artifact-signer/templates/tests/test-sign-verify.yaml @@ -18,7 +18,7 @@ spec: buildah push ttl.sh/sigstore-test:5m securityContext: privileged: true - runAsUser: 1000 + runAsUser: 0 containers: - name: cosign image: "{{ .Values.configs.cosign_deploy.image.registry }}/{{ .Values.configs.cosign_deploy.image.repository }}@{{ .Values.configs.cosign_deploy.image.version }}"