Skip to content

Add GitLab package signing key to the keyring

Balasankar 'Balu' C requested to merge import-package-signing-key into main

What does this MR do?

We already add the repo signing GPG key. However, to install local rpm files, you need the package signing key also present in the keyring, else you get "Failed to validate GPG signature for " errors. This MR explicitly adds the key.

PS: It is only actually required for RPM, but for consistency I added it to deb also.

Related issues

Closes: #399

Author's checklist

  • Merge request:
    • Corresponding Issue raised and reviewed by the GET maintainers team.
    • Merge Request Title and Description are up to date, accurate, and descriptive
    • MR targeting the appropriate branch
    • MR has a green pipeline
    • MR has no new security alerts in the widget from the Secret Detection and IaC Scan (SAST) jobs.
  • Code:
    • Check the area changed works as expected. Consider testing it in different environment sizes (1k,3k,10k,etc.).
    • Documentation created/updated in the same MR.
    • If this MR adds an optional configuration - check that all permutations continue to work.
    • For Terraform changes: setup a previous version environment, then run a terraform plan with your new changes and ensure nothing will be destroyed. If anything will be destroyed and this can't be avoided please add a comment to the current MR.
  • Create any follow-up issue(s) to support the new feature across other supported cloud providers or advanced configurations. Create 1 issue for each provider/configuration. Contact the Quality Enablement team if unsure.
Edited by Balasankar 'Balu' C

Merge request reports