@@ -22,7 +22,6 @@ var _ = g.Describe("[sig-imageregistry][Serial][Suite:openshift/registry/serial]
22
22
)
23
23
24
24
g .It ("can push a signed image to openshift registry and verify it" , func () {
25
- g .Skip ("disable because containers/image: https://github.com/containers/image/pull/570" )
26
25
g .By ("building a signer image that knows how to sign images" )
27
26
output , err := oc .Run ("create" ).Args ("-f" , signerBuildFixture ).Output ()
28
27
if err != nil {
@@ -90,7 +89,7 @@ var _ = g.Describe("[sig-imageregistry][Serial][Suite:openshift/registry/serial]
90
89
o .Expect (out ).To (o .ContainSubstring ("Logged in" ))
91
90
92
91
// Sign and copy the memcached image into target image stream tag
93
- g .By ("signing the memcached:latest image and pushing it into openshift registry" )
92
+ g .By ("signing a just-built image and pushing it into openshift registry" )
94
93
out , err = pod .Exec (strings .Join ([]string {
95
94
"GNUPGHOME=/var/lib/origin/gnupg" ,
96
95
"skopeo" , "--debug" ,
@@ -99,10 +98,14 @@ var _ = g.Describe("[sig-imageregistry][Serial][Suite:openshift/registry/serial]
99
98
"--registries.d" , "/this/does/not/exist" ,
100
99
101
100
"copy" ,
"--sign-by" ,
"[email protected] " ,
101
+ "--src-creds=" + user + ":" + token ,
102
102
"--dest-creds=" + user + ":" + token ,
103
- // TODO: test with this turned to true as well
104
- "--dest-tls-verify=false" ,
105
- "docker://docker.io/library/memcached:latest" ,
103
+
104
+ // Expect to use /run/secrets/kubernetes.io/serviceaccount/ca.crt
105
+ "--src-cert-dir=/run/secrets/kubernetes.io/serviceaccount" ,
106
+ "--dest-cert-dir=/run/secrets/kubernetes.io/serviceaccount" ,
107
+
108
+ "docker://" + signerImage ,
106
109
"docker://" + signedImage ,
107
110
}, " " ))
108
111
fmt .Fprintf (g .GinkgoWriter , "output: %s\n " , out )
0 commit comments