ci: sign plugins-index.json in-repo, drop worker signing dependency
Pair with the worker-side simplification on the librefang PR — the worker is now a pure transport (no key material, no signing) and this repo's CI takes over signature production. scripts/sign-plugins-index.mjs reads REGISTRY_PRIVATE_KEY from a GitHub Actions secret, signs plugins-index.json with Ed25519, and writes plugins-index.json.sig alongside it. Aborts loudly when the secret is missing so a misconfigured CI can't silently ship an unsigned payload. The workflow now runs build → sign → commit (.json + .sig) → push → poke worker /refresh. The worker fetches the committed .json + .sig verbatim and stores both — the daemon then verifies against the embedded pubkey it ships with. Closes PR review CRITICAL #1: the worker is no longer a sign-anything oracle reachable via REGISTRY_REFRESH_TOKEN. Trust root is now this repo's branch protection + Actions secret scope, not a token any CI job that can talk to stats.librefang.ai can use to mint signatures. Note: the keypair was rotated as part of this change (PR not yet merged so no daemon TOFU pins exist). New pubkey: ClGa0Ucap8NdrKAy1rw9Tt6A9I8eg4zJ53+xIuKMuq0= The plugins-index.json.sig committed here is signed with the matching new private key, in lockstep with the daemon EMBEDDED_REGISTRY_PUBKEY constant and all three worker [vars] entries.
This commit is contained in:
1 parent
ff6f3f2b25
commit
74745f1f20
3 files changed
+79
-1
No files matched your search
@@ -45,11 +45,16 @@ jobs:
|
||||
node scripts/build-plugins-index.mjs
|
||||
node scripts/build-registry-index.mjs
|
||||
|
||||
- name: Sign plugins-index.json
|
||||
env:
|
||||
REGISTRY_PRIVATE_KEY: ${{ secrets.REGISTRY_PRIVATE_KEY }}
|
||||
run: node scripts/sign-plugins-index.mjs
|
||||
|
||||
- name: Commit regenerated indexes if changed
|
||||
run: |
|
||||
git config user.name "github-actions[bot]"
|
||||
git config user.email "github-actions[bot]@users.noreply.github.com"
|
||||
git add plugins-index.json registry-index.json
|
||||
git add plugins-index.json plugins-index.json.sig registry-index.json
|
||||
if git diff --cached --quiet; then
|
||||
echo "indexes already up-to-date"
|
||||
else
|
||||
|
||||
Reference in new issue
Block a user