Skip to content

Commit

Permalink
feat(container.provider): update of container instance digest through…
Browse files Browse the repository at this point in the history
… signature verification service

Signed-off-by: SimoneFiorani <[email protected]>
  • Loading branch information
sfiorani committed Mar 21, 2024
1 parent 5e7e511 commit 3823331
Show file tree
Hide file tree
Showing 2 changed files with 38 additions and 10 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,7 @@ public class ContainerInstance implements ConfigurableComponent, ContainerOrches

private ContainerOrchestrationService containerOrchestrationService;
private Set<ContainerSignatureValidationService> availableContainerSignatureValidationService = new HashSet<>();
private String signatureExtractedDigest;

private State state = new Disabled(new ContainerInstanceOptions(Collections.emptyMap()));

Expand Down Expand Up @@ -91,15 +92,24 @@ public void updated(Map<String, Object> properties) {

try {
ContainerInstanceOptions newProps = new ContainerInstanceOptions(properties);
this.signatureExtractedDigest = null;

if (!newProps.getEnforcementDigest().isPresent()) {

logger.info(
"Container configuration doesn't include enforcement digest. Validating with Container Signature Validation service");

if (newProps.getSignatureTrustAnchor().isPresent()) {
ValidationResult containerSignatureValidated = validateContainerImageSignature(newProps);
this.signatureExtractedDigest = containerSignatureValidated.imageDigest().orElse("?");
logger.info("Container signature validation result for {}@{}({}) - {}",
newProps.getContainerImage(), this.signatureExtractedDigest,
newProps.getContainerImageTag(),
containerSignatureValidated.isSignatureValid() ? "OK" : "FAIL");
} else {
logger.info("No trust anchor available. Signature validation skipped.");
}

if (newProps.getSignatureTrustAnchor().isPresent()) {
ValidationResult containerSignatureValidated = validateContainerImageSignature(newProps);
String imageDigest = containerSignatureValidated.imageDigest().orElse("?");
logger.info("Container signature validation result for {}@{}({}) - {}", newProps.getContainerImage(),
imageDigest, newProps.getContainerImageTag(),
containerSignatureValidated.isSignatureValid() ? "OK" : "FAIL");
} else {
logger.info("No trust anchor available. Signature validation skipped.");
}

if (newProps.isEnabled()) {
Expand Down Expand Up @@ -342,7 +352,9 @@ private void startMicroservice(final ContainerInstanceOptions options) {
int maxRetries = options.getMaxDownloadRetries();
int retryInterval = options.getRetryInterval();

final ContainerConfiguration containerConfiguration = options.getContainerConfiguration();
final ContainerConfiguration containerConfiguration = options.getEnforcementDigest().isPresent()
? options.getContainerConfiguration()
: options.getContainerConfiguration(signatureExtractedDigest);

int retries = 0;
while ((unlimitedRetries || retries < maxRetries) && !Thread.currentThread().isInterrupted()) {
Expand Down Expand Up @@ -425,4 +437,4 @@ public State onDisabled() {

}

}
}
Original file line number Diff line number Diff line change
Expand Up @@ -394,6 +394,22 @@ public ContainerConfiguration getContainerConfiguration() {
.setRuntime(getRuntime()).setEnforcementDigest(getEnforcementDigest()).build();
}

public ContainerConfiguration getContainerConfiguration(String signatureExtractedDigest) {

Optional<String> finalEnforcementDigest = (!signatureExtractedDigest.equals("?"))
? Optional.of(signatureExtractedDigest)
: getEnforcementDigest();

return buildPortConfig(ContainerConfiguration.builder()).setContainerName(getContainerName())
.setImageConfiguration(buildImageConfig()).setEnvVars(getContainerEnvList())
.setVolumes(getContainerVolumeList()).setPrivilegedMode(this.privilegedMode)
.setDeviceList(getContainerDeviceList()).setFrameworkManaged(true).setLoggingType(getLoggingType())
.setContainerNetowrkConfiguration(buildContainerNetworkConfig())
.setLoggerParameters(getLoggerParameters()).setEntryPoint(getEntryPoint())
.setRestartOnFailure(getRestartOnFailure()).setMemory(getMemory()).setCpus(getCpus()).setGpus(getGpus())
.setRuntime(getRuntime()).setEnforcementDigest(finalEnforcementDigest).build();
}

private List<Integer> parsePortString(String ports) {
List<Integer> tempArray = new ArrayList<>();
if (!ports.isEmpty()) {
Expand Down

0 comments on commit 3823331

Please sign in to comment.