Skip to content

Tracking support for full private Sigstore setup with model validation controller and custom OIDC provider #34

@SequeI

Description

@SequeI

Summary

This issue is meant to track the enhancements and fixes being done upstream to support running a fully private Sigstore instance alongside the model validation controller, with compatibility for a custom OIDC client, such as Keycloak.

Goals:
Enable the use of a custom OIDC issuer and client (e.g. Keycloak) with proper audience handling.

Allow the trust configuration to work end-to-end without hardcoding assumptions like sigstore as the audience/client ID.

Ensure the model validation controller can interoperate smoothly with a private Fulcio/Rekor/TSA stack.

Support standard OAuth redirect flows to improve compatibility with modern OIDC providers (Google, Keycloak, etc.).

Dependencies & Related PRs:

This issue will serve as a central tracker for anyone wanting to deploy a self-hosted Sigstore setup without relying on the public infrastructure.

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions