Explanatory

These are presentations backed by slides.

Short Introduction

What is Asfaload and when is it useful?

Asfaload workflow

Discover the steps leading you from creating a key pair to signing your release artifacts.

Demos

Managing key pairs with the CLI

See how to generate and share keys, including using existing ssh keys.

Generating a signers file

See how to generate your multisig config.

Publishing your signers file

See how to publish your signers file to your github repo.

This is the trust anchor to validate signatures are legit and generated by owners of the repo. We protect the branch to avoid erroneous updates to that file as its availability is required to validate signatures.

Register your repo's signers file

When your signers file is published in your repo, you need to register is with the Asfaload backend.

Activate your signers file

When your signers file is registered on the Asfaload backend, all signers need to sign it to become active.