Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions .github/workflows/release-models.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,7 @@ on:
permissions:
contents: read
packages: write
id-token: write # cosign keyless OIDC signing

env:
REGISTRY: ghcr.io/layer87-labs
Expand Down Expand Up @@ -54,6 +55,12 @@ jobs:
docker push ${{ env.REGISTRY }}/tei-model-init:${{ env.MODEL_TAG }}
docker push ${{ env.REGISTRY }}/tei-model-init:latest

- name: Install cosign
uses: sigstore/cosign-installer@v3

- name: Sign image (keyless via OIDC, by digest)
run: scripts/sign-image.sh "${{ env.REGISTRY }}/tei-model-init:${{ env.MODEL_TAG }}"

reranker-model:
if: >
github.event_name == 'push' ||
Expand Down Expand Up @@ -85,6 +92,12 @@ jobs:
docker push ${{ env.REGISTRY }}/tei-reranker-model-init:${{ env.MODEL_TAG }}
docker push ${{ env.REGISTRY }}/tei-reranker-model-init:latest

- name: Install cosign
uses: sigstore/cosign-installer@v3

- name: Sign image (keyless via OIDC, by digest)
run: scripts/sign-image.sh "${{ env.REGISTRY }}/tei-reranker-model-init:${{ env.MODEL_TAG }}"

whisper-model:
if: >
github.event_name == 'push' ||
Expand Down Expand Up @@ -116,3 +129,9 @@ jobs:
.
docker push ${{ env.REGISTRY }}/whisper:${{ env.MODEL_TAG }}
docker push ${{ env.REGISTRY }}/whisper:latest

- name: Install cosign
uses: sigstore/cosign-installer@v3

- name: Sign image (keyless via OIDC, by digest)
run: scripts/sign-image.sh "${{ env.REGISTRY }}/whisper:${{ env.MODEL_TAG }}"
13 changes: 13 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ on:
permissions:
contents: write
packages: write
id-token: write # cosign keyless OIDC signing

env:
REGISTRY: ghcr.io/layer87-labs
Expand Down Expand Up @@ -65,6 +66,18 @@ jobs:
make docker/tei-runtime VERSION=${{ env.VERSION }}
docker push ${{ env.REGISTRY }}/tei-runtime:${{ env.VERSION }}

# ── Sign images (keyless cosign via GitHub OIDC, by digest) ─────────

- name: Install cosign
uses: sigstore/cosign-installer@v3

- name: Sign code images
run: |
scripts/sign-image.sh \
"${{ env.REGISTRY }}/inference-router:${{ env.VERSION }}" \
"${{ env.REGISTRY }}/tei-base:${{ env.VERSION }}" \
"${{ env.REGISTRY }}/tei-runtime:${{ env.VERSION }}"

# ── Helm chart (OCI → ghcr.io) ───────────────────────────────────────

- name: Package and push Helm chart
Expand Down
23 changes: 23 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -101,6 +101,29 @@ All images are published to `ghcr.io/layer87-labs/`:

All images run as non-root with no privilege escalation.

### Verify image signatures

Images built by the release workflows are signed with
[cosign](https://github.com/sigstore/cosign) keyless via GitHub OIDC. Verify by
digest against the exact workflow identity:

```bash
IMAGE=ghcr.io/layer87-labs/inference-router
DIGEST=$(docker buildx imagetools inspect "$IMAGE:<version>" --format '{{json .Manifest}}' | jq -r .digest)

cosign verify \
--certificate-identity 'https://github.com/layer87-labs/inference-stack/.github/workflows/release.yml@refs/heads/main' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
"$IMAGE@$DIGEST"
```

`release.yml` signs `inference-router`, `tei-base` and `tei-runtime`.
`release-models.yml` signs `tei-model-init`, `tei-reranker-model-init` and
`whisper`; for those, use the identity
`https://github.com/layer87-labs/inference-stack/.github/workflows/release-models.yml@refs/heads/main`
(for manual runs, the ref is the branch the workflow was started from).
Images published before signing was added are unsigned.

## Build

```bash
Expand Down
17 changes: 17 additions & 0 deletions scripts/sign-image.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
#!/usr/bin/env bash
# Sign pushed container images by digest with keyless cosign (GitHub OIDC).
# Usage: scripts/sign-image.sh <repository:tag>...
# Requires: cosign, docker, a prior `docker push`, and `id-token: write`.
set -euo pipefail

for ref in "$@"; do
repo="${ref%:*}"
digest="$(docker inspect --format '{{range .RepoDigests}}{{println .}}{{end}}' "${ref}" \
| grep "^${repo}@sha256:" | head -n1)"
if [ -z "${digest}" ]; then
echo "no pushed digest found for ${ref}" >&2
exit 1
fi
cosign sign --yes "${digest}"
echo "Signed ${digest}" >> "${GITHUB_STEP_SUMMARY:-/dev/null}"
done
Loading