How to enable Collection signing with manual signatures

I want to upload signatures to my collection and it seems I have to enable collection signing before that.

The instructions at Enabling collection signing - Galaxy NG instruct to “Create a signing service”, etc…

I however don’t want any automatic signing. I only want to sign manually with key I have on my smart card whenever I make a release. I already have a .asc detached signature ready to go. How can I enable collection signing and upload the signatures?

You can manually upload signatures as described within these API docs:

https://pulpproject.org/pulp_ansible/restapi/#tag/Content:-Collection_Signatures/operation/content_ansible_collection_signatures_create

Although this must be handled separately from the ansible-galaxy collection publish step.

Additionally there is other additional information that must be retrieved from the API after publishing in order to make the request described above.

Here is an example galaxy-ng-test-container/playbooks/playbook.yml at 82d673db3a81056fa7a83aaf5f16676a94d23c5b · ansible/galaxy-ng-test-container · GitHub

I now spent more time trying to overcome the friction here.

I can list my published versions and get the pulp_hrefs with

curl -H "Accept: application/json" "https://galaxy.ansible.com/api/pulp/api/v3/content/ansible/collection_versions/?namespace=eaaltonen&name=pgp"

It seems I also need to include also a repo ID to the signature publish request. I can list repositories (providing auth token) with

read -s galaxy_token
printf 'Authorization: Token %s\n' "$galaxy_token" | curl -H "@-" -H "Accept: application/json" 'https://galaxy.ansible.com/api/pulp/api/v3/repositories/'

Listing me six different possible repositories. I tried to upload the signature for 0.1.0 to the repository with the pulp_label: "pipeline": "staging", but the response was {"detail":"You do not have permission to perform this action."}.

The galaxy-ng docs step " Enabling support for signature upload on the galaxy server" mentions setting a gpg keyring specifying the allowed PGP public primary keys associated with the repository, which does sound very sensible.

I have some questions:

  1. Are one or more of the listed repositories associated with my namespace or collection specifically?
  2. How am I to identify which repository is to be used for signature uploads.
  3. If the PGP public primary key registration is required before uploading signatures, how would I go about setting that up with my collection hosted in galaxy.ansible.com?

The primary key I would prefer using is CB3D07FA546F37665B912A7413E456655EFEEBEA, and possibly maybe a Trusted Timestamping Authority later.