I however don’t want any automatic signing. I only want to sign manually with key I have on my smart card whenever I make a release. I already have a .asc detached signature ready to go. How can I enable collection signing and upload the signatures?
Listing me six different possible repositories. I tried to upload the signature for 0.1.0 to the repository with the pulp_label: "pipeline": "staging", but the response was {"detail":"You do not have permission to perform this action."}.
The galaxy-ng docs step " Enabling support for signature upload on the galaxy server" mentions setting a gpg keyring specifying the allowed PGP public primary keys associated with the repository, which does sound very sensible.
I have some questions:
Are one or more of the listed repositories associated with my namespace or collection specifically?
How am I to identify which repository is to be used for signature uploads.
If the PGP public primary key registration is required before uploading signatures, how would I go about setting that up with my collection hosted in galaxy.ansible.com?
The primary key I would prefer using is CB3D07FA546F37665B912A7413E456655EFEEBEA, and possibly maybe a Trusted Timestamping Authority later.