Next steps¶
Adapting this to your organization¶
- Keyless signing from CI. If your CI runs on GitHub Actions and public Sigstore is
acceptable, drop the key:
rattler-buildandpixi uploadcan produce CEP-27 attestations with the workflow's OIDC identity, and the registry'sCONDA_ATTESTATION_ISSUERSandCONDA_ATTESTATION_IDENTITIESpin which workflows may publish. The key-based path in this walkthrough is for shops that cannot. - A private Sigstore. Between the two: run your own Fulcio and Rekor and point the trust policy at them. The verification code path is the same as keyless.
- One DNS name and a real CA.
ak.internalwith Caddy's internal CA stands in for your internal DNS and PKI. Swap the certificate and the hostname; nothing else changes, because every client already trusts a CA you distribute through thetrustrepository. - Tokens. Mint consumer tokens with a repository selector covering the virtual channel's members until a virtual-scoped token can read through (requested). Rotate the CI token with the staging repository's token API; it never needs more than staging.
- More channels. Add
biocondaor an internal-devchannel as members of the virtual channel at the right priority; the ownership rule applies to every hosted member. - Air gap. Replace the conda-forge proxy with a replicated hosted copy on the inside, keep everything else. Builds already assume no internet.
- Real CI runners. Attach runners to the registry network and drop the podman-in-podman from
image/build.sh; it exists only because rootlesspodman buildcannot join a named network.
Watch for in the clients¶
- pixi exposing rattler's install-time attestation verification: then
verify-attestations.shbecomes a config setting. - pixi using
indexed_timestampforexclude-newer, which closes the backdating gap. - Syft emitting PURLs for conda packages, which would let Grype deduplicate its conda findings.
In Artifact Keeper¶
- Proxy downloads recorded in the download audit (needs a schema change).
- Shards served through the conda-forge proxy and for virtual channels.
- Scan-on-proxy for conda, so public packages are scanned before they are served, not only after they are installed.
- A repository-level "N of M packages attested" count, which needs an aggregate API.
The 1.11.0 release notes list everything that came out of this walkthrough; the lab notes are the record behind them.