4e9444d7

By: Michael Lynch <git@mtlynch.io>

Explain scoped Skopeo insecure policy

Document why the docker-archive policy can accept unsigned images safely: it only applies to the local archive built by the deploy script while the default policy rejects every other source.

Suite timing

Time to Start Worker time Duration Time to finish Idle
Config 2s 7s 7s 10s 2s
Eval 8s 59s 59s 1m08s 0s
Build 13s 7m18s 2m08s 2m21s 45s
Suite 2s 8m25s 2m19s 2m21s 47s

Timeline

0s10s20s30s40s50s1m1m10s1m20s1m30s2m20s