CI, releases, and signing
Understand the gates from pull request through edge images, tagged releases, Helm publication, and Cosign verification.
The rolling :edge channel is test software; production installs should pin a tagged chart and immutable image digests.
Continuous integration
CI covers Go modules, envtest, web build/coverage, browser tests, Helm rendering, and disjoint Kind E2E buckets.
Edge channel
Changes on main publish rolling :edge images and immutable sha-<short> tags for all released components.
Tagged release
A v tag builds and signs images, packages the OCI chart, creates release notes, and publishes official modules.
RELEASE PATH
Release images carry Cosign signatures recorded in the public Sigstore Rekor transparency log. Verify any released or edge image with the cosign.pub key at the repo root. Pre-rotation releases (v0.2.0-beta.7 and earlier) used the retired Ed25519 key and require cosign-legacy.pub with the --insecure-ignore-tlog=true flag (see Key Rotation for trust continuity).
Signing is mandatory and fail-closed: without COSIGN_PRIVATE_KEY the release job fails before anything is pushed. Every signing job (release.yaml, publish-edge.yaml, images.yaml and republish-modules.yaml) runs in the release-signing environment, whose deployment policy admits only master and v* tags, so a run on any other ref never receives the key. Images are pushed by digest, signed and verified, and only then tagged, so a published tag always names a signed image.