2.0 KiB
CI Security, Signing and Provenance
.gitea/workflows/casan-supply-chain.yml is the release gate for Control
Panel images. It fails closed if the runner is missing osv-scanner or Trivy,
if any high/critical source or image issue is found, if a main-branch commit is
not cryptographically signed, or if the attestation signing key is unavailable.
Runner bootstrap
Provision the dedicated ci-runner with Node 22/npm (for npm sbom), Docker,
OpenSSL, Python 3, Git, OSV-Scanner v2 and Trivy. Verify each downloaded scanner
against vendor provenance/checksums before making it available under a trusted
system directory (/usr/local/bin or /usr/bin). Do not make a project-local
binary trusted.
The job generates a CycloneDX SBOM (npm sbom), queries OSV live for lockfile
vulnerabilities, and uses Trivy for filesystem, secret, misconfiguration and
image scanning. This follows the tools' supported source/image scan interfaces.
Gitea secrets and policies
Configure these repository/organization values before enabling production deployments:
| Value | Purpose |
|---|---|
GITEA_TOKEN |
Push only the scanned images to the Gitea registry. Scope: package write. |
CASAN_ATTESTATION_PRIVATE_KEY |
PEM private key held in the secret manager; signs SLSA/in-toto provenance. |
CASAN_REGISTRY (variable) |
Optional container registry host; defaults to the Gitea server host. |
Register the matching public key in the release-verification trust store, then
protect main: require the CASAN Supply Chain and Provenance check, reject
force-pushes, require signed commits, and restrict direct pushes to enrolled
signers. The workflow independently checks every new commit's Git signature;
branch UI policy alone is not treated as evidence.
The output artifact contains npm.cyclonedx.json, OSV/Trivy reports, image
digest files, the signed provenance.intoto.json and public key. Copy only the
two digest references into infra/production/casan-prod.env; tags are refused
by production preflight.