ci: SLSA L3 build-provenance attestations on the publish arm - #227
Merged
Merged
Conversation
Each per-leg publish job in _build-platform.yml now closes with a GitHub artifact attestation (actions/attest-build-provenance v4.2.2, SHA-pinned — the pin tamatebako/tebako's release.yml carries) over the exact staged bytes it ships: the runtime package, its .sha256 sidecars, the .manifest.json shard, and the detached .asc set when the signing arm ran (the signer converges them into runtime-packages/). The .leg-complete marker is dot-hidden and the non-shipped *-ucrt-ruby*.dll copies are rm'd by the publish step, so the glob names neither. The arm rides the publish job's own gate (inputs.publish && !inputs.audit), so build/audit runs never attest. The publish job declares attestations:write + id-token:write, and publish.yml's four platform caller jobs grant both down to the reusable workflow (a caller's grants cap the callee's — the same flow as the windows-signing id-token grant).
The publish.yml callers carried the grant, but the four build caller jobs also invoke _build-platform.yml — and its publish job's new permissions block requests attestations: write on every invocation, build or not. A reusable workflow never elevates past the caller's grant (the caller comment says so itself), so GitHub refused every build-* run at startup (startup_failure, no jobs spawned).
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Fans out the SLSA Build L3 artifact-attestation arm that landed in tamatebako/tebako#694 to this factory's publish path (unblocked now that #226 has merged).
.github/workflows/_build-platform.yml— the per-legpublishjob (the shipping leg:Publish the leg's runtime package (spec 13 §2a)+Sign the leg's release assets (spec 09 §5)) gains a terminalAttest build provenancestep (actions/attest-build-provenance@4d101475d8b20a2381f78447822ac1eab6504dd8, v4.2.2 — the same pin tebako's release.yml carries) withsubject-path: runtime-packages/*: exactly the staged bytes the uploader ships — the runtime package (exe + env image), its.sha256sidecars, the.manifest.jsonshard, plus the detached.ascset when the signing arm ran (the gem's signer converges them intoruntime-packages/, its default local dir). The dot-hidden.leg-completemarker is never globbed, and the non-shipped*-ucrt-ruby*.dllboot-smoke copies are rm'd by the publish step before the attest runs.attestations: write+id-token: write;.github/workflows/publish.yml's four platform caller jobs (windows,linux-gnu,linux-musl,macos) grantattestations: writedown to the reusable workflow — the same flow as the existing windows-signingid-token: writegrant (a caller'spermissionscap the callee's).Gate parity
The attest step carries the same gate as the leg's publish/sign steps: the publish job's own
Build CI, audit runs, and non-publish dispatches skip the publish job outright, so they never attest. A leg whose build failed dies at the artifact-completeness guard before the attest step.
Verification
python3 -c yaml.safe_loadon both touched workflows: parse OK.actionlint .github/workflows/publish.yml .github/workflows/_build-platform.yml: identical findings to main (four pre-existing shellcheck notes in unrelated steps; this change adds none).bundle exec rspec: 295 examples, 0 failures, 38 pending (environmental — unchanged from main).spec/build_workflow_spec.rb(the ci: run the spawn-edge acceptance per leg before publish (#211) #226 step-ordering assertions): 22 examples, 0 failures — the publish-job ordering contract (download → guard → publish → sign) is preserved; the attest step appends after sign, so no spec change was needed.Consumers verify with
gh attestation verify <asset> --repo tamatebako/tebako-runtime-ruby.Not to be merged by the author — the orchestrator merges after checks go green.