The op1st Tekton release pipeline signs with the cosign-signing-key Secret in op1st-pipelines, provisioned upstream from op1st-emea-b4mad GitOps. The in-repo secrets/cosign.pub diverged from that key (sha256 0c945708... vs 377836e4...) — verifying Tekton-signed releases against the local key would fail. Local material was never the source of truth and is now removed. Removed: - secrets/cosign.pub (stale, wrong key) - secrets/cosign-signing-key.enc.yaml (SOPS-encrypted local copy, redundant with op1st-gitops) - secrets/.gitkeep - scripts/cosign-keygen.sh (helper for the removed local material) - .gitignore allowlist for secrets/* (replaced with full secrets/ ignore) Updated: - README "Verifying Releases" → fetch cosign.pub from op1st-emea-b4mad at manifests/applications/op1st-pipelines-tokens/cosign-signing-key.pub. Both branch-tip and commit-pinned (8a3c55e5...) variants. - ADR + runbook: operator precondition now references the op1st-emea-b4mad path instead of secrets/cosign.pub. Refs: forgejo-mcp-a2y, forgejo-mcp-d4b
45 lines
601 B
Text
45 lines
601 B
Text
*.log
|
|
|
|
# Build output
|
|
build/
|
|
dist/
|
|
forgejo-mcp
|
|
|
|
# Environment variables
|
|
.env
|
|
.env.local
|
|
.env.development.local
|
|
.env.test.local
|
|
.env.production.local
|
|
.envrc
|
|
|
|
# IDE and editor files
|
|
.idea/
|
|
.vscode/
|
|
*.swp
|
|
*.swo
|
|
*~
|
|
|
|
# OS files
|
|
.DS_Store
|
|
Thumbs.db
|
|
|
|
# Claude Code settings
|
|
.claude/settings.local.json
|
|
.claude/scheduled_tasks.lock
|
|
|
|
.social-media/
|
|
|
|
# Beads / Dolt files (added by bd init)
|
|
.dolt/
|
|
*.db
|
|
.beads-credential-key
|
|
|
|
# Python bytecode cache
|
|
__pycache__/
|
|
worktrees/
|
|
.claude/scheduled_tasks.lock
|
|
|
|
# Defense-in-depth: catch SOPS scratch files and any future secrets/ usage.
|
|
secrets/
|
|
.~decrypted*.enc.yaml
|