Skip to content

Conversation

@mburke5678
Copy link
Contributor

https://issues.redhat.com/browse/OSDOCS-17653

Link to docs preview:

QE review:

  • QE has approved this change.

@mburke5678 mburke5678 added this to the Continuous Release milestone Dec 11, 2025
@openshift-ci openshift-ci bot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Dec 11, 2025
@mburke5678
Copy link
Contributor Author

@QiWang19 @lyman9966 For this PR, I only removed the Technology Preview statements, as I understand there are no user-facing changes in the TP to GA promotion. Can you please verify if this is correct?

@ocpdocs-vale-bot
Copy link
Collaborator

🤖 Thu Dec 11 15:58:26 - Prow CI generated the docs preview:

https://103803--ocpdocs-pr.netlify.app/openshift-enterprise/latest/nodes/nodes-sigstore-using.html

Copy link
Member

@QiWang19 QiWang19 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM on removing the requirement to enable the FeatureGate for the BYOPKI use case.

@wking Could you take a look at the note on mirroring signatures to make sure it's relevant and necessary for users in this use case?

* You have a sigstore-supported public key infrastructure (PKI) key, a Bring Your Own Public Key Infrastructure (BYOPKI) certificate, or provide a link:https://docs.sigstore.dev/cosign/signing/overview/[Cosign public and private key pair] for signing operations.
* You have a signing process in place to sign your images.
* You have access to a registry that supports Cosign signatures, if you are using Cosign signatures.
* If registry mirrors are configured for the {product-title} release image repositories, `quay.io/openshift-release-dev/ocp-release` and `quay.io/openshift-release-dev/ocp-v4.0-art-dev`, before enabling the Technology Preview feature set, you must mirror the sigstore signatures for the {product-title} release images into your mirror registry. Otherwise, the default `openshift` cluster image policy, which enforces signature verification for the release repository, blocks the ability of the Cluster Version Operator to move the CVO pod to new nodes, preventing the node update that results from the feature set change.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Mirroring the sigstore signatures seems to still be valid guidance for air-gapped or disconnected environments. However, mentioning the Technology Preview feature set here might no longer be relevant. Would it make sense to adjust this section to focus on recommending signature mirroring explicitly for disconnected users? @wking What are your thoughts?

* You have access to a registry that supports Cosign signatures, if you are using Cosign signatures.
* If registry mirrors are configured for the {product-title} release image repositories, `quay.io/openshift-release-dev/ocp-release` and `quay.io/openshift-release-dev/ocp-v4.0-art-dev`, before enabling the Technology Preview feature set, you must mirror the sigstore signatures for the {product-title} release images into your mirror registry. Otherwise, the default `openshift` cluster image policy, which enforces signature verification for the release repository, blocks the ability of the Cluster Version Operator to move the CVO pod to new nodes, preventing the node update that results from the feature set change.
+
You can use the `oc image mirror` command to mirror the signatures. For example:
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

non-blocker: CLID-453 introduces the oc-mirror tool to mirror sigstore signatures by default and is currently in the testing phase for version 4.21. Once the documentation is ready, we could consider adding a follow-up PR to include the oc-mirror tool as an alternative method for mirroring signatures.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Requested help from the writer associated with CLID-43.

@ocpdocs-previewbot
Copy link

🤖 Fri Dec 12 22:08:45 - Prow CI generated the docs preview:

https://103803--ocpdocs-pr.netlify.app/openshift-enterprise/latest/nodes/nodes-sigstore-using.html

@openshift-ci
Copy link

openshift-ci bot commented Dec 12, 2025

@mburke5678: all tests passed!

Full PR test history. Your PR dashboard.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

branch/enterprise-4.21 size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants