defenseunicorns / uds-software-factory

🏭 UDS Software Factory Integration / Wayfinding Repo
GNU Affero General Public License v3.0
9 stars 1 forks source link

Spike: Explore where in-toto attestations will go once they are created #56

Closed Racer159 closed 4 months ago

Racer159 commented 5 months ago

Is your feature request related to a problem? Please describe.

We need to have a place that we can upload workload attestations into that is query-able and could be used for policy validation, auditing, and dashboarding by later UDS tooling.

Describe the solution you'd like

Describe alternatives you've considered

We could avoid attestations / in-toto but there is a lot of nice auditing capabilities that we would be missing out on without it.

Additional context

Something like Archivista (https://github.com/in-toto/archivista) could work for this and is already in the in-toto family - we could also look at simpler solutions nearer term as well though.

ericwyles commented 4 months ago

Selected Archivista for this and created a separate issue for tracking building that package: https://github.com/defenseunicorns/uds-package-archivista/issues/3