Keyless image signing with memory independent of image size
G
Gold Cobra
The SSCA artifact signing and verify steps export the image to a docker-archive tar and cosign reads it whole, so the step's memory grows with the image. A 4.7 GB image needs a 16Gi limit to sign. On Kubernetes build infra sequential steps share the pod and every container gets the largest limit, so every build pod becomes a 16Gi pod.
Request: sign the image digest instead of the tarball for keyless (Fulcio) signing, as cosign sign image@digest does, so memory stays constant.