Implements sections 3-4 of openspec/changes/release-tools-image/tasks.md.
Produces .tekton/release-tools/ containing:
PipelineRuns (PaC):
- on-pull-request-build.yaml — CEL gated to files.any.exists() under
image/release-tools/ or .tekton/release-tools/. Builds + verifies +
SBOM-scans the image; no push.
- on-tag-publish.yaml — triggered on refs/tags/release-tools/v* push.
Pipeline shape (TOCTOU-safe per adversarial review L1):
fetch-source → resolve-tag → build → verify-tools → syft-scan →
push-by-digest → cosign-sign-by-digest → cosign-attach-sbom →
promote-tag (only NOW does vMAJOR.MINOR.PATCH resolve).
Reusable Tasks:
- build-image.yaml — buildah build against image/release-tools/Containerfile
- verify-image-tools.yaml — runs built image, asserts every bundled
tool's --version + the offline-npx + shell-present scenarios
- syft-scan-image.yaml — CycloneDX SBOM via syft (uses release-tools
image itself — dogfooding)
- resolve-release-tools-tag.yaml — strips refs/tags/release-tools/ prefix
- push-image-by-digest.yaml — pushes manifest by digest only, no tag
- cosign-sign-image-by-digest.yaml — signs by digest with
cosign-signing-key (optional: false, fail-closed per spec asymmetry)
- cosign-attach-sbom.yaml — attaches SBOM as cosign attestation
- promote-image-tag.yaml — crane/skopeo tag promotion AFTER sign
Defensive CEL:
- .tekton/on-tag-push-release.yaml — added negative-CEL annotation so a
release-tools/vX.Y.Z tag push CANNOT accidentally fire the forgejo-mcp
release pipeline (adversarial review A1).
Verifier T12 PASS: yaml syntax (all 11 files), pre-commit (gitleaks),
openspec validate release-tools-image — all green.
Registry path is TBD (working assumption quay.io/operate-first/release-tools)
— flagged in pipeline header comments; coordinate with op1st-emea-b4mad
maintainers before first tag-publish run.
Refs: forgejo-mcp-1b4
55 lines
1.6 KiB
YAML
55 lines
1.6 KiB
YAML
apiVersion: tekton.dev/v1
|
|
kind: Task
|
|
metadata:
|
|
name: release-tools-verify-image-tools
|
|
annotations:
|
|
tekton.dev/displayName: "verify bundled tool versions in release-tools image"
|
|
spec:
|
|
params:
|
|
- name: IMAGE_REF
|
|
description: Full image reference to run (tag or tag@digest).
|
|
type: string
|
|
- name: STORAGE_DRIVER
|
|
description: buildah/podman storage driver.
|
|
type: string
|
|
default: vfs
|
|
steps:
|
|
- name: verify-tools
|
|
image: quay.io/buildah/stable:latest
|
|
securityContext:
|
|
privileged: true
|
|
script: |
|
|
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
IMAGE="$(params.IMAGE_REF)"
|
|
echo "Verifying tools in: ${IMAGE}"
|
|
|
|
run() {
|
|
buildah run \
|
|
--storage-driver="$(params.STORAGE_DRIVER)" \
|
|
--isolation=chroot \
|
|
"$(buildah from --storage-driver="$(params.STORAGE_DRIVER)" "${IMAGE}")" \
|
|
-- /bin/sh -c "$1"
|
|
}
|
|
|
|
# Verify each required tool reports a version (fails build if any missing).
|
|
buildah from --storage-driver="$(params.STORAGE_DRIVER)" --name verify-ctr "${IMAGE}"
|
|
|
|
check() {
|
|
echo "--- $1 ---"
|
|
buildah run --storage-driver="$(params.STORAGE_DRIVER)" verify-ctr -- /bin/sh -c "$1"
|
|
}
|
|
|
|
check "go version"
|
|
check "syft version"
|
|
check "goreleaser --version"
|
|
check "cosign version"
|
|
check "jq --version"
|
|
check "curl --version"
|
|
check "node --version"
|
|
check "npm --version"
|
|
check "/bin/sh -c 'echo shell-ok'"
|
|
|
|
buildah rm verify-ctr
|
|
echo "All tool checks passed."
|