Repository navigation
ci(moss): add SLSA provenance, SPDX SBOM generation, and Exit Gate artifact promotion - #5582
chiajunglien wants to merge 1 commit into
Conversation
|
Note Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported. |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
0d5ac24 to
6068583
Compare
6068583 to
8565c48
Compare
8565c48 to
bc17a6f
Compare
| run: | | ||
| STAGING_IMAGE_URI="us-docker.pkg.dev/${PROJECT_NAME}/${BUILD_REPO}/${INPUTS_IMAGE_NAME}@${IMAGE_DIGEST}" | ||
| if [[ "${PROJECT_NAME}" == "cloud-tpu-images" ]]; then | ||
| SBOM_BUCKET="gs://artifactanalysis-us-189282287250" |
There was a problem hiding this comment.
This workflow never pushes to cloud-tpu-images. We can remove this if-else condition block.
|
|
||
| echo "Promoting ${STAGING_IMAGE}@${IMAGE_DIGEST} to ${PROD_IMAGE} via Exit Gate..." | ||
| ACCESS_TOKEN="$(gcloud auth print-access-token)" | ||
| PROMOTE_URL="https://artifactregistry.googleapis.com/v1/projects/${PROJECT_NAME}/locations/us/repositories/${PROD_REPO}:promoteArtifact" |
There was a problem hiding this comment.
This logic to call promoteArtifact is duplicate across several workflow files. Please refactor this into a bash script .github/scripts/promote_artifacts.sh to reduce the complexity of the workflow.
There was a problem hiding this comment.
| echo "dockerfile: $DOCKERFILE" | ||
|
|
||
| - name: Install Syft SBOM generator | ||
| run: | |
There was a problem hiding this comment.
Instead of inline python script, can we use anchore/sbom-action/download-syft@v0 to setup syft?
There was a problem hiding this comment.
Done! Switched to anchore/sbom-action/download-syft@e22c389904149dbc22b58101806040fa8d37a610 # v0 in both build_and_push_docker_image.yml and build_package.yml in #5601.
| if [[ "${PROJECT_NAME}" == "cloud-tpu-images" ]]; then | ||
| SBOM_BUCKET="gs://artifactanalysis-us-189282287250" | ||
| else | ||
| SBOM_BUCKET="gs://artifactanalysis-us-770040921623" |
There was a problem hiding this comment.
Added this to Github variable, use ${SBOM_BUCKET} instead.
Description
This PR updates MaxText's GitHub Actions Docker and PyPI release workflows to achieve Managed Open Source Software (MOSS) Phase 1 compliance (SLSA build provenance, SPDX SBOM generation and Container Analysis / SCILo ingestion, and staging-to-production promotion via the Artifact Registry
:promoteArtifactExit Gate API):.github/workflows/build_and_push_docker_image.ymlso builds targetingmaxtext-imagesfirst push tomaxtext-images-staging, invoke the Artifact Registry:promoteArtifactREST API (attachment_behavior: "PUBLIC_BCID_VSA_ONLY") to evaluate BCID policies via the Exit Gate, and apply tags tomaxtext-imagesonce promoted..github/workflows/pypi_release.ymland.github/workflows/promote_docker_image.ymlto promote images frommaxtext-images-stagingtomaxtext-imagesvia:promoteArtifactbefore applying release/latest tags..github/workflows/promote_public_docker_image.ymlto support promoting customer-facing TPU images (tpu_pre_trainingandtpu_post_training) incloud-tpu-imagesfrommaxtext-images-stagingtomaxtext-images.provenance: mode=maxandsbom: trueondocker/build-push-actionin.github/workflows/build_and_push_docker_image.yml.sbom.spdx.json) usingsyftimmediately after the image build and uploads/exports it viagcloud artifacts sbom loadandgcloud artifacts sbom exportfor Container Analysis and BCID/SCILo ingestion..github/workflows/build_package.ymlto generate an SPDX JSON SBOM (sbom/maxtext-wheel.spdx.json) for the built wheel usingsyftand upload it as a workflow artifact (maxtext-wheel-sbom)..github/workflows/pypi_release.ymland.github/workflows/release_pipeline.ymlto generate signed Sigstore SLSA build provenance (actions/attest-build-provenance) and SPDX SBOM attestations (actions/attest-sbom), publish PyPI attestations (attestations: true), and attach the wheel SBOM viagcloud artifacts sbom loadduring release image promotion.Tests
https://github.com/AI-Hypercomputer/maxtext/actions/runs/37619618755
Checklist
Before submitting this PR, please make sure (put X in square brackets):
gemini-reviewlabel.