The op1st Tekton release pipeline signs with the cosign-signing-key
Secret in op1st-pipelines, provisioned upstream from op1st-emea-b4mad
GitOps. The in-repo secrets/cosign.pub diverged from that key (sha256
0c945708... vs 377836e4...) — verifying Tekton-signed releases against
the local key would fail. Local material was never the source of truth
and is now removed.
Removed:
- secrets/cosign.pub (stale, wrong key)
- secrets/cosign-signing-key.enc.yaml (SOPS-encrypted local copy, redundant with op1st-gitops)
- secrets/.gitkeep
- scripts/cosign-keygen.sh (helper for the removed local material)
- .gitignore allowlist for secrets/* (replaced with full secrets/ ignore)
Updated:
- README "Verifying Releases" → fetch cosign.pub from op1st-emea-b4mad
at manifests/applications/op1st-pipelines-tokens/cosign-signing-key.pub.
Both branch-tip and commit-pinned (8a3c55e5...) variants.
- ADR + runbook: operator precondition now references the op1st-emea-b4mad
path instead of secrets/cosign.pub.
Refs: forgejo-mcp-a2y, forgejo-mcp-d4b