Commit 87d40e35 authored by Raffaele's avatar Raffaele Committed by GitHub

adding signer to workflow (#9444)

* adding signer to workflow

* Update .circleci/signer/sign_image.py
Co-authored-by: default avatarcoderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* Update .circleci/signer/sign_image.py
Co-authored-by: default avatarcoderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* Update .circleci/signer/sign_image.py
Co-authored-by: default avatarcoderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* Update .circleci/signer/sign_image.py
Co-authored-by: default avatarcoderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* Update .circleci/signer/sign_image.py
Co-authored-by: default avatarcoderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

* adding capability to get the digest directly from the script. Moving the script folder inside ops

* changing log from info to debug

* removed unused vars

* removed old files

* testing signer

* testing signer

* adding python orb

* upgrading runner image from ubuntu-2204:2022.07.1 to ubuntu-2204:2024.01.1

* using python3 directly

* using single quotes instead of dowble quotes for key into dict

* minor changes

* setting config back after completing test

* testing without export of vars

* completing changes

* setting git.revision

* fixed image tag input

---------
Co-authored-by: default avatarcoderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
parent 6120d22f
...@@ -338,6 +338,19 @@ jobs: ...@@ -338,6 +338,19 @@ jobs:
name: Tag name: Tag
command: | command: |
./ops/scripts/ci-docker-tag-op-stack-release.sh <<parameters.registry>>/<<parameters.repo>> $CIRCLE_TAG $CIRCLE_SHA1 ./ops/scripts/ci-docker-tag-op-stack-release.sh <<parameters.registry>>/<<parameters.repo>> $CIRCLE_TAG $CIRCLE_SHA1
- when:
condition: "<<parameters.publish>>"
steps:
- gcp-oidc-authenticate:
service_account_email: GCP_SERVICE_ATTESTOR_ACCOUNT_EMAIL
- run:
name: Sign
command: |
cd ./ops/signer
export IMAGE_PATH="<<parameters.registry>>/<<parameters.repo>>/<<parameters.docker_name>>:<<pipeline.git.revision>>"
pip3 install -r requirements.txt
python3 sign_image.py
contracts-bedrock-coverage: contracts-bedrock-coverage:
......
urllib3
requests
\ No newline at end of file
This diff is collapsed.
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment