4 ms·
We use GPG to sign git code commits so that we have some sort of protected audit trail for checkins and to make it much more difficult for a transient endpoint
by evgen 4y ago
We use GPG to sign git code commits so that we have some sort of protected audit trail for checkins and to make it much more difficult for a transient endpoint compromise to lead to a malicious code push. Putting the GPG keys into a yubikey make this much easier and it also adds a two-factor auth path that is much more convenient for developers.
- sneakerblack 4y agoYup! Exactly Both git commit signing and 2FA. Some DevOps engineers also use it to SSH into prod whenever there's a problems with the servers
- aborsy 4y agoOh, yeah, works well for signing code. We used it for various other things, such as password management and authentication.