Uh oh!
There was an error while loading. Please reload this page.
implement docker trust as plugin - #6121
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
thaJeztah
commented
Jun 5, 2025
It's currently expected that this fails, because the e2e test require the plugin to be installed (what we currently don't do). This error is interesting though; for some reason it shows an error about API version mismatch, but after that it shows Waiting for docker daemon to become available at ssh://penguin@172.18.0.3Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Cannot connect to the Docker daemon at http://docker.example.com./ Is the docker daemon running?Error response from daemon: client version 1.50 is too new. Maximum supported API version is 1.42Client: Version: 28.2.0-dev API version: 1.42 (downgraded from 1.50) Go version: go1.24.3 Git commit: d271c02 Built: Mon Jun 2 15:32:03 2025 OS/Arch: linux/amd64 Context: defaultServer: Docker Engine - Community Engine: Version: 23.0.6 API version: 1.42 (minimum version 1.12) |
3fea064 to
e612749Compare
This comment was marked as resolved.
This comment was marked as resolved.
bc004be to
6c5320cCompareb50e878 to
51a9993Compare| github.com/docker/go v1.5.1-1.0.20160303222718-d30aec9fd63c // indirect | ||
| github.com/docker/go-events v0.0.0-20250808211157-605354379745 // indirect | ||
| github.com/docker/go-metrics v0.0.1 // indirect | ||
| github.com/docker/libtrust v0.0.0-20160708172513-aabc10ec26b7 // indirect |
There was a problem hiding this comment.
Unfortunately, this brings back libtrust as an indirect dependency; still looking what pulls it in (but probably docker/distribution)
thaJeztah
commented
Nov 4, 2025
OK, so when removing the |
fd1c1a2 to
615e313Compare98b079f to
f0c94bfCompare449ea26 to
6730f40Compare54b98ec to
824028fComparemove the `trust` subcommands to a plugin, so that the subcommands can be installed separate from the `docker trust` integration in push/pull (for situations where trust verification happens on the daemon side). make binary go build -o /usr/libexec/docker/cli-plugins/docker-trust ./cmd/docker-trust docker info Client: Version: 28.2.0-dev Context: default Debug Mode: false Plugins: buildx: Docker Buildx (Docker Inc.) Version: v0.24.0 Path: /usr/libexec/docker/cli-plugins/docker-buildx trust: Manage trust on Docker images (Docker Inc.) Version: unknown-version Path: /usr/libexec/docker/cli-plugins/docker-trust docker trust --help Usage: docker trust [OPTIONS] COMMAND Extended build capabilities with BuildKit Options: -D, --debug Enable debug logging Management Commands: key Manage keys for signing Docker images signer Manage entities who can sign Docker images Commands: inspect Return low-level information about keys and signatures revoke Remove trust for an image sign Sign an image Run 'docker trust COMMAND --help' for more information on a command. Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
skip cmd/docker-trust in tests, as it's a separate module. Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
Create a copy of the registry package to use, so that code used only for trust can be removed from the cli/internal package. Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
Prevent the linter from recursing to other modules (cmd/docker-trust), which don't have their dependencies vendored. Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
Just a quick experiment to see if we can move the
trustsubcommands to a plugin, so that the subcommands can be installed separate from thedocker trustintegration in push/pull (for situations where trust verification happens on the daemon side).makes the CLI binaries somewhat smaller as well:
Before:
After:
- What I did
- How I did it
- How to verify it
- Human readable description for the release notes
- A picture of a cute animal (not mandatory but encouraged)