Skip to content

ci(moss): add SLSA provenance, SPDX SBOM generation, and Exit Gate artifact promotion - #5582

Closed
chiajunglien wants to merge 1 commit into
mainfrom
emma/moss-docker-promote-sbom
Closed

chiajunglien wants to merge 1 commit into
mainfrom
emma/moss-docker-promote-sbom

Conversation

@chiajunglien

@chiajunglien chiajunglien commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Description

This PR updates MaxText's GitHub Actions Docker and PyPI release workflows to achieve Managed Open Source Software (MOSS) Phase 1 compliance (SLSA build provenance, SPDX SBOM generation and Container Analysis / SCILo ingestion, and staging-to-production promotion via the Artifact Registry :promoteArtifact Exit Gate API):

  1. Staging-to-Production Promotion via Artifact Registry Exit Gate (Task 1.2):
  • Updates .github/workflows/build_and_push_docker_image.yml so builds targeting maxtext-images first push to maxtext-images-staging, invoke the Artifact Registry :promoteArtifact REST API (attachment_behavior: "PUBLIC_BCID_VSA_ONLY") to evaluate BCID policies via the Exit Gate, and apply tags to maxtext-images once promoted.
  • Updates .github/workflows/pypi_release.yml and .github/workflows/promote_docker_image.yml to promote images from maxtext-images-staging to maxtext-images via :promoteArtifact before applying release/latest tags.
  • Adds .github/workflows/promote_public_docker_image.yml to support promoting customer-facing TPU images (tpu_pre_training and tpu_post_training) in cloud-tpu-images from maxtext-images-staging to maxtext-images.
  1. SLSA Build Provenance & SPDX SBOM Generation for Docker Images (Task 1.3 & Task 1.4):
  • Enables provenance: mode=max and sbom: true on docker/build-push-action in .github/workflows/build_and_push_docker_image.yml.
  • Generates an SPDX JSON SBOM (sbom.spdx.json) using syft immediately after the image build and uploads/exports it via gcloud artifacts sbom load and gcloud artifacts sbom export for Container Analysis and BCID/SCILo ingestion.
  1. SLSA Build Provenance & SPDX SBOM for MaxText PyPI Wheel (Task 1.7):
  • Updates .github/workflows/build_package.yml to generate an SPDX JSON SBOM (sbom/maxtext-wheel.spdx.json) for the built wheel using syft and upload it as a workflow artifact (maxtext-wheel-sbom).
  • Updates .github/workflows/pypi_release.yml and .github/workflows/release_pipeline.yml to generate signed Sigstore SLSA build provenance (actions/attest-build-provenance) and SPDX SBOM attestations (actions/attest-sbom), publish PyPI attestations (attestations: true), and attach the wheel SBOM via gcloud artifacts sbom load during release image promotion.

Tests

https://github.com/AI-Hypercomputer/maxtext/actions/runs/37619618755

Checklist

Before submitting this PR, please make sure (put X in square brackets):

  • I have performed a self-review of my code. For an optional AI review, add the gemini-review label.
  • I have necessary comments in my code, particularly in hard-to-understand areas.
  • I have run end-to-end tests tests and provided workload links above if applicable.
  • I have made or will make corresponding changes to the doc if needed, including adding new documentation pages to the relevant Table of Contents (toctree directive) as explained in our documentation.

@gemini-code-assist

Copy link
Copy Markdown

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

Comment thread .github/workflows/build_and_push_docker_image.yml Fixed
@codecov

codecov Bot commented Oct 7, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@chiajunglien
chiajunglien force-pushed the emma/moss-docker-promote-sbom branch from 0d5ac24 to 6068583 Compare October 7, 2026 09:25
@chiajunglien
chiajunglien marked this pull request as ready for review October 7, 2026 09:27
@chiajunglien
chiajunglien marked this pull request as draft October 7, 2026 09:42
@chiajunglien
chiajunglien force-pushed the emma/moss-docker-promote-sbom branch from 6068583 to 8565c48 Compare October 7, 2026 09:49
@chiajunglien
chiajunglien marked this pull request as ready for review October 7, 2026 09:51
@chiajunglien
chiajunglien force-pushed the emma/moss-docker-promote-sbom branch from 8565c48 to bc17a6f Compare October 7, 2026 12:39
run: |
STAGING_IMAGE_URI="us-docker.pkg.dev/${PROJECT_NAME}/${BUILD_REPO}/${INPUTS_IMAGE_NAME}@${IMAGE_DIGEST}"
if [[ "${PROJECT_NAME}" == "cloud-tpu-images" ]]; then
SBOM_BUCKET="gs://artifactanalysis-us-189282287250"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This workflow never pushes to cloud-tpu-images. We can remove this if-else condition block.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done! Removed the if-else block and switched to SBOM_BUCKET: ${{ vars.SBOM_BUCKET }} in #5601 (and #5604).


echo "Promoting ${STAGING_IMAGE}@${IMAGE_DIGEST} to ${PROD_IMAGE} via Exit Gate..."
ACCESS_TOKEN="$(gcloud auth print-access-token)"
PROMOTE_URL="https://artifactregistry.googleapis.com/v1/projects/${PROJECT_NAME}/locations/us/repositories/${PROD_REPO}:promoteArtifact"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This logic to call promoteArtifact is duplicate across several workflow files. Please refactor this into a bash script .github/scripts/promote_artifacts.sh to reduce the complexity of the workflow.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done! Extracted the :promoteArtifact logic into .github/scripts/promote_artifacts.sh in #5603, and updated the workflows (build_and_push_docker_image.yml, promote_docker_image.yml, pypi_release.yml, and promote_public_docker_image.yml) to call this script in #5604.

echo "dockerfile: $DOCKERFILE"

- name: Install Syft SBOM generator
run: |

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Instead of inline python script, can we use anchore/sbom-action/download-syft@v0 to setup syft?

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done! Switched to anchore/sbom-action/download-syft@e22c389904149dbc22b58101806040fa8d37a610 # v0 in both build_and_push_docker_image.yml and build_package.yml in #5601.

if [[ "${PROJECT_NAME}" == "cloud-tpu-images" ]]; then
SBOM_BUCKET="gs://artifactanalysis-us-189282287250"
else
SBOM_BUCKET="gs://artifactanalysis-us-770040921623"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added this to Github variable, use ${SBOM_BUCKET} instead.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done! Updated to use SBOM_BUCKET: ${{ vars.SBOM_BUCKET }} in #5601 (for build_and_push_docker_image.yml) and #5604 (for pypi_release.yml).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants