Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Project: recover an artifact trust chain

Last updated: 1 Oct 20269 min read
project
AdvancedBy AITrove Editorial

Run this drill with disposable repositories, a test registry, synthetic claims data, and a restricted cloud role. Create a protected release job and a separate pull-request test job. Before injecting faults, capture the reviewed commit, trusted build identity, image digest, signing identity, dependency sources, and recovery-region pull result. Use a canary credential that can be revoked after the exercise.

Cross and reject trust boundaries

Produce a malicious test artifact in the untrusted job: give it a report-like name while embedding a script and an unsafe archive path. The protected job may inspect a bounded structured report but must not execute or promote that artifact. Attempt to assume the deployment role from a feature branch, another repository, and a job with the wrong audience; all three must be denied. Build the release from the protected commit using a private package and a temporary secret mount. Publish a public name collision and verify the clean build still resolves the approved private package. Scan the image, cache, logs, and metadata for the canary credential; revoke it after the check.

Output
Artifact trust drill gates
Untrusted artifact: cannot execute or become release binary
Cloud role: only protected deployment job assumes it
Build credential: absent from layers, history, cache, and logs
Dependency: source and checksum match approved lock
Promotion: scanned digest equals deployed digest
Signer: new identity accepted; wrong identity denied
Recovery: current and rollback digests pull and run

Exercise registry and rollback failure

Move a mutable test tag after scan approval and confirm the deployment gate rejects the changed digest. Stage a new signing identity alongside the old one, admit a new-signed canary, and deny an unrelated signer. Delay registry replication for one release so the recovery gate blocks failover until the exact digest is present and pull-tested. Mark an old untagged digest for cleanup while a rollback manifest still references it; the retention gate must preserve it. Replace a Pod and perform a rollback in the disposable cluster to prove the registry serves the prior release rather than relying on a node cache.

Cost and verification

Record build minutes, registry storage and transfer, signature verification time, and denied role assumptions. The acceptance record needs one reviewed source revision, one approved digest, a tested signer identity, a clean credential scan, and working current and rollback pulls in the recovery target. A green test badge, source registry rule, or already running Pod is insufficient on its own. Delete only test resources after retaining the evidence.

Common Mistakes

  • Do not reuse an untrusted binary because tests passed.
  • Do not verify a tag and deploy a later tag value.
  • Do not expire an untagged digest still required for rollback.

Connected lessons

devops
project
Storage details