UNCLASSIFIED - NO CUI

Edit Notary ADR text and merge

This template is ONLY used for enhancement requests. Bug reporting or new feature request issues should use the other template options for issue submission.

Current Behavior

After presenting the ADR to management, we received some improvement recommendations. We need to update the ADR and either consider these things, or we need to update the documentation to make it more clear why these things have been considered, and are not being implemented.

Purpose

Allay concerns and fears from other Platform One team members

Plan

  • Discuss/refute the statement "Prismacloud (Twistlock) defenders already ensure the provenance of containers when pulling, and at runtime", i.e. the statement that Notary doesn't gain us anything
  • Discuss/refute the statement "OPA/Gatekeeper already ensure the provenance of containers when pulling, and at runtime", i.e. the statement that Notary doesn't gain us anything
  • Discuss "just use simple signing", discuss whether the Notary implementation of TUF is improved over simple signing
  • Call out shortcomings with containerd/crio
  • Call out that Notary v2 = OCI 2
  • Call out that we are using DoD CA signed root key
  • Standardize/implement process of who has access to root key, and how it's stored

Acceptance Criteria

  • All issues above are addressed, documented, and resolved.
Edited by Tim Seagren