Skip to content

Sign the Vibes #857

@gorkem

Description

@gorkem

Describe the problem you're trying to solve
Many users already rely on Cosign for signing and attesting OCI artifacts. Today you can use it to sign KitOps ModelKits - but it's a two step / two tool process.

Describe the solution you'd like
To provide a seamless end-to-end experience within KitOps, we should add analogous kit sign and kit attest subcommands to the kit CLI. This will allow users to sign ModelKits and attach attestations without switching tools.

New subcommands:

  • kit sign
  • kit attest
  • kit verify

Follow the same flag semantics as cosign for sing and attest but verify should cover both ModelKit signing and attestation verification.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions