Keys

The release signing key

The public half, the allowed_signers file and the verify command. A release is signed when its SHA256SUMS.sig verifies with this key.

build host / keys

The key

The release signing key

Ed25519
The public half of the key every release's SHA256SUMS is signed with; namespace igneum-release.
256 SHA256:umhm59z0pvL2OCPwi0zl1VcRCr4poHILz9zbzWEGCLk igneum-release (ED25519)

The files

96 bytes
sha256 3b77424e466ac2242fa921ee858c8a6445cea42094fa8e475d20555c212ace5f
124 bytes
sha256 3365522a2c2392f9bed1cd1e03bf29d6c25734209f8d82b58632779c15607b3a
1019 bytes
sha256 43872f041e0a139aef15bee6946369f1db6968e8cdc34aa1fbbe5213dd70622d

Verify a release

In the directory holding a release's SHA256SUMS and SHA256SUMS.sig, with allowed_signers from this page:
ssh-keygen -Y verify -f allowed_signers -I igneum-release -n igneum-release -s SHA256SUMS.sig < SHA256SUMS
sha256sum -c SHA256SUMS
Or from a checkout: infra/release/verify.sh <component> <version>. The private half is on one machine and is never on a host, in a repository or in a message.
Igneum Labs LLC. Written 2026-10-11 13:31:11 UTC by the release host at each put; nothing here is a launch.