To improve the security and trustworthiness of a Salt-driven infrastructure, being able to verify GPG signed commits is IMHO a key requirement.
Otherwise the trust is external to GitFS and Salt has to rely on the security of the git repository hosting.
It should be possible to switch either all or individual GitFS (States and especially Pillars) repositories to require valid and trusted GPG signatures, based on the Master's GPG keyring.
It might make sense to set a trust-level threshold when verifying against a known key.
+1
@eliasp, thanks for the report.
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
If this issue is closed prematurely, please leave a comment and we will gladly reopen the issue.
Keep this one open!
Thank you for updating this issue. It is no longer marked as stale.
Is there a planned version for this being implemented? Or expected timeline?
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
If this issue is closed prematurely, please leave a comment and we will gladly reopen the issue.
Don't think this has been added yet - comment to keep open.
Thank you for updating this issue. It is no longer marked as stale.
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.
If this issue is closed prematurely, please leave a comment and we will gladly reopen the issue.
Still an issue AFAIK.
Thank you for updating this issue. It is no longer marked as stale.
Most helpful comment
Is there a planned version for this being implemented? Or expected timeline?