Skip to content

Plugin signing and verifying - #6

Closed
scottrigby wants to merge 78 commits into
plugin-systemfrom
plugin-signing
Closed

scottrigby wants to merge 78 commits into
plugin-systemfrom
plugin-signing

Conversation

@scottrigby

@scottrigby scottrigby commented Jul 25, 2025 •

Copy link
Copy Markdown
Owner

This PR adds plugin signing, verifying and commands described in HIP 0026

to-do:

…mand type flag

Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
…e postrender

Signed-off-by: Scott Rigby <scott@r6by.com>
…mplete:

	// NOTE(thomastaylor312): I am leaving this code commented out here. During
	// the implementation of post-render, it was brought up that if we are
	// relying on plugins, we should actually use the plugin system so it can
	// properly handle multiple OSs. This will be a feature add in the future,
	// so I left this code for reference. It can be deleted or reused once the
	// feature is implemented

Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
… unmarshall strict

Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
…pe (legacy plugins are either cli or download)

Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
fix nil pointer dereference for tests

Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
…subprocess and Wasm). Move fields to the applicable config structs. TODO update tests and testdata YAML to match

Signed-off-by: Scott Rigby <scott@r6by.com>
…tch, and update tests to match

Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
…t but with the wrong value. Give better error instead

Signed-off-by: Scott Rigby <scott@r6by.com>
…plugin.yaml fully if they set apiVersion to v1

Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
scottrigby and others added 18 commits August 5, 2025 02:18
Signed-off-by: Scott Rigby <scott@r6by.com>
… it's consistent)

Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
… way to preserve file mode for executables

Signed-off-by: Scott Rigby <scott@r6by.com>
…update plugin OCI installer accordingly

Signed-off-by: Scott Rigby <scott@r6by.com>
…cy_downloader_convert

Fix legacy metadata downloader convert
Signed-off-by: Scott Rigby <scott@r6by.com>

fix plugin HTTP tarball support

Signed-off-by: Scott Rigby <scott@r6by.com>

fix plugin local tarball support

Signed-off-by: Scott Rigby <scott@r6by.com>

Plugin signing and provenance support

Signed-off-by: Scott Rigby <scott@r6by.com>

Add verify flag to plugin install

Signed-off-by: Scott Rigby <scott@r6by.com>

Add installed plugin provenance tracking, with errors, warnings, and info during plugin commands

Signed-off-by: Scott Rigby <scott@r6by.com>

Allow plugin verify cmd to verify directories for installed signed plugins

Signed-off-by: Scott Rigby <scott@r6by.com>

Replace tarball-based hashing with idempotent directory-based hashing

Signed-off-by: Scott Rigby <scott@r6by.com>

Fix plugin package --sign case where tarball was created even if no signing key was found

Signed-off-by: Scott Rigby <scott@r6by.com>

update plugin package command to sign by default. bypass with --sign=false. emit warning if so

Signed-off-by: Scott Rigby <scott@r6by.com>

Fix TestIsRemoteHTTPArchive caused by optimization added in commit 00cbd42 that changed the behavior of isRemoteHTTPArchive

Signed-off-by: Scott Rigby <scott@r6by.com>

Fix TestExtractPluginInSubdirectory test failure

The test was failing with "destination already exists" error because it
was calling installer.Install() directly without going through the
InstallWithOptions wrapper that checks for existing installations.

Added cleanup of the destination directory before installation to match
the behavior of the wrapper function.

Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
Signed-off-by: Scott Rigby <scott@r6by.com>
@scottrigby
scottrigby changed the base branch from plugin-types to plugin-system August 13, 2025 07:48
Signed-off-by: Scott Rigby <scott@r6by.com>
Comment thread pkg/cmd/plugin_install.go
shouldVerify := o.verify

// Check if this is a local directory installation (for development)
if localInst, ok := i.(*installer.LocalInstaller); ok && !localInst.SupportsVerification() {

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

should we skip verification for legacy plugins too?

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the new codebase can sign legacy plugins too. I think we should encourage this with all plugins including legacy. Right now --verify defaults to true (users can bypass it with --verify=false and they get a warning).

}

// Also remove the .prov file if it exists
provFile := p.Dir() + ".prov"

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is this needed? The os.RemoveAll(p.Dir()) should clean up everything?

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ah, no, the .prov file sits next to the plugin dir in the HELM_PLUGINS directory.

truncated example from my laptop now:

% ls -lah $(go run ./cmd/helm env HELM_PLUGINS)
total 8
drwxr-xr-x@ 10 r6by  staff   320B Aug 13 05:05 .
drwxr-xr-x@  3 r6by  staff    96B Jan 21  2025 ..
drwxr-xr-x@  4 r6by  staff   128B Aug 13 05:05 example-cli
-rw-r--r--@  1 r6by  staff   897B Aug 13 05:05 example-cli.prov
lrwxr-xr-x@  1 r6by  staff    83B Aug 13 01:54 example-extism-getter -> /Users/r6by/code/github.com/scottrigby/h4-simple-plugin-types/example-extism-getter
lrwxr-xr-x@  1 r6by  staff    76B Aug 13 01:18 example-getter -> /Users/r6by/code/github.com/scottrigby/h4-simple-plugin-types/example-getter

@scottrigby

Copy link
Copy Markdown
Owner Author

this is complete in upstream helm/helm

@scottrigby scottrigby closed this Aug 30, 2025
scottrigby added a commit that referenced this pull request Aug 13, 2026
…26-6061

backport of helm#32450

updated with:

```
go get google.golang.org/grpc@v1.82.1
go mod tidy
```

example actions failure:
https://github.com/helm/helm/actions/runs/31733009013/job/94557780520

```
  Vulnerability #1: GO-2026-6061
      Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2
      transport server implementation in google.golang.org/grpc
    More info: https://pkg.go.dev/vuln/GO-2026-6061
    Module: google.golang.org/grpc
      Found in: google.golang.org/grpc@v1.80.0
      Fixed in: google.golang.org/grpc@v1.82.1
      Example traces found:
  Error:       #1: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Close
  Error:       #2: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Header
  Error:       #3: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Read
  Error:       #4: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.RecvCompress
  Error:       #5: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.TrailersOnly
  Error:       #6: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Write
  Error:       #7: pkg/action/lazyclient.go:49:17: action.lazyClient.init calls sync.Once.Do, which eventually calls transport.NewHTTP2Client
  Error:       #8: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.Stream.ReadMessageHeader
  Error:       #9: pkg/action/lazyclient.go:49:17: action.lazyClient.init calls sync.Once.Do, which eventually calls transport.http2Client.Close
  Error:       #10: pkg/action/lazyclient.go:49:17: action.lazyClient.init calls sync.Once.Do, which eventually calls transport.http2Client.GracefulClose
  Error:       #11: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.http2Client.NewStream
```

Signed-off-by: Scott Rigby <scott@r6by.com>
scottrigby added a commit that referenced this pull request Aug 13, 2026
…26-6061 (helm#32536)

backport of helm#32450

updated with:

```
go get google.golang.org/grpc@v1.82.1
go mod tidy
```

example actions failure:
https://github.com/helm/helm/actions/runs/31733009013/job/94557780520

```
  Vulnerability #1: GO-2026-6061
      Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2
      transport server implementation in google.golang.org/grpc
    More info: https://pkg.go.dev/vuln/GO-2026-6061
    Module: google.golang.org/grpc
      Found in: google.golang.org/grpc@v1.80.0
      Fixed in: google.golang.org/grpc@v1.82.1
      Example traces found:
  Error:       #1: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Close
  Error:       #2: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Header
  Error:       #3: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Read
  Error:       #4: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.RecvCompress
  Error:       #5: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.TrailersOnly
  Error:       #6: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.ClientStream.Write
  Error:       #7: pkg/action/lazyclient.go:49:17: action.lazyClient.init calls sync.Once.Do, which eventually calls transport.NewHTTP2Client
  Error:       #8: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.Stream.ReadMessageHeader
  Error:       #9: pkg/action/lazyclient.go:49:17: action.lazyClient.init calls sync.Once.Do, which eventually calls transport.http2Client.Close
  Error:       #10: pkg/action/lazyclient.go:49:17: action.lazyClient.init calls sync.Once.Do, which eventually calls transport.http2Client.GracefulClose
  Error:       #11: pkg/repo/repotest/server.go:128:32: repotest.NewOCIServer calls registry.NewRegistry, which eventually calls transport.http2Client.NewStream
```

Signed-off-by: Scott Rigby <scott@r6by.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Sponsor
SponsoredKunjungi sekarang
Promo