## Summary - Enable OIDC + API key authentication on zot with anonymous pull preserved - Enforce tag immutability for version tags - Adopt commit-SHA-based container image tagging Details in the [[harden-zot-registry]] Mikado chain (`mise run docs-mikado harden-zot-registry`). ## Test plan - [ ] Anonymous pull still works - [ ] Unauthenticated push fails (401) - [ ] CI container builds pass with new auth and tagging - [ ] `mise run services-check` passes 🤖 Generated with [Claude Code](https://claude.com/claude-code) Reviewed-on: https://forge.ops.eblu.me/eblume/blumeops/pulls/231 |
||
|---|---|---|
| .. | ||
| .gitkeep | ||
| add-container-versioning-prereq.infra.md | ||
| feature-agent-change-process.feature.md | ||
| feature-authentik-mikado-chain.infra.md | ||
| feature-deploy-authentik.feature.md | ||
| feature-forgejo-authentik-oidc.feature.md | ||
| harden-zot-mikado-cards.ai.md | ||
| plan-deploy-authentik.doc.md | ||