MAQPNADocs

Verify releases

Check MAQPNA binaries, images and the Helm chart before you run them, with SHA-256 checksums, cosign keyless signatures and SBOM attestations.

Every MAQPNA release is signed. Binaries carry a cosign keyless signature from the release signing workflow, images and the Helm chart are signed by the release workflow, and every image has an SPDX SBOM attestation. maqpna verify checks all of them in one command; the install scripts check binaries for you.

flowchart LR
  A[Download binary<br/>+ .sigstore.json + checksums.txt] --> B[maqpna verify binary]
  C[Images and chart<br/>release registry] --> D[maqpna verify image / chart<br/>--sbom]
  B & D --> E[maqpna verify release V]
  E --> F[Pin image.digest<br/>in your values]

Goal#

Run only artefacts whose checksum and signature you checked, and pin the image digests you verified.

Prerequisites#

  • cosign 2.x or later on PATH (maqpna verify calls it).
  • Network access to the release assets and the registry, or the files copied next to you.

Where releases are published#

What Where
Binaries, archives, packages, SBOMs, checksums.txt and per-file .sigstore.json maqpna.com/download and maqpna.com/releases (canonical)
Mirror https://dl.maqpna.com/<version>/bin/<os>/<arch>/<binary> (with .sha256 and .sigstore.json)
Images <release registry>/<image>:<X.Y.Z> (and :<X.Y>), linux/amd64 and arm64
Helm chart oci://<release registry>/charts/maqpna

The release registry is listed on maqpna.com/download.

The signer identities are built into maqpna verify: binaries are signed by the signed-release workflow, images and the chart by the release workflow at the release tag, both with the OIDC issuer https://token.actions.githubusercontent.com. maqpna verify binary -h and maqpna verify image -h print the exact identities, which you can pass to cosign yourself.

Steps#

1. Let the installer verify the CLI#

curl -fsSL https://maqpna.com/install.sh | sh -s -- --version v0.1.1 --cosign

The script downloads checksums.txt and the raw binary, checks its SHA-256, then checks the cosign signature (when cosign is on PATH, or always with --cosign; --no-cosign skips it). Other options: --bin NAME (repeatable), --dir DIR, --mirror (dl.maqpna.com), --base URL. On Windows, install.ps1 takes the same options.

2. Verify a downloaded binary#

Download maqpna_linux_amd64, maqpna_linux_amd64.sigstore.json and checksums.txt from maqpna.com/releases, then:

maqpna verify binary maqpna_linux_amd64 --checksums checksums.txt

Real output for the v0.1.1 Linux binary:

ok    maqpna_linux_amd64                                           sha256
ok    maqpna_linux_amd64                                           signature
2 checks, 0 failed

A changed file fails, and the exit status is 3:

FAIL  maqpna_tampered                                              signature              error during command execution: failed to verify signature: could not verify message: invalid signature when validating ASN.1 encoded signature
1 checks, 1 failed

The same checks with standard tools (IDENTITY_REGEXP is the binary signer from maqpna verify binary -h):

grep ' maqpna_linux_amd64$' checksums.txt | sha256sum --check      # shasum -a 256 --check on macOS
cosign verify-blob maqpna_linux_amd64 --bundle maqpna_linux_amd64.sigstore.json \
  --certificate-identity-regexp "$IDENTITY_REGEXP" \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com
maqpna_linux_amd64: OK
Verified OK

3. Verify images and the chart#

maqpna verify image "$REGISTRY/maqpna-gateway:0.1.1" --sbom
maqpna verify chart --version 0.1.1 --registry "$REGISTRY"

verify image checks the cosign signature against the release workflow at a v* tag (--identity or --identity-regexp override it) and, with --sbom, the SPDX SBOM attestation. Equivalent cosign commands (IDENTITY is the release workflow at the tag, from maqpna verify image -h):

cosign verify "$REGISTRY/maqpna-gateway:0.1.1" \
  --certificate-identity "$IDENTITY" \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com
cosign verify-attestation --type spdxjson "$REGISTRY/maqpna-gateway:0.1.1" \
  --certificate-identity "$IDENTITY" \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

4. Verify a whole release#

maqpna verify release v0.1.1 --sbom --binaries ./downloads

It verifies the 11 images and the chart signed by the release workflow at the tag, and every binary in --binaries (with their .sigstore.json files and checksums.txt). --no-images and --no-chart skip parts. It exits 3 when any check fails.

5. Pin what you verified#

image:
  digest: sha256:...     # the digest you verified; wins over the tag

6. Verify an air-gap bundle#

maqpna verify bundle ./maqpna-airgap-0.1.1 --require-signature --key cosign.pub

See Air-gapped install.

What a release contains#

Artefact Platforms
maqpna, maqpna-sovereign, maqpna-install linux (amd64, arm64, ppc64le, s390x), darwin (amd64, arm64, universal), windows (amd64, arm64)
maqpna-gateway, maqpna-identity linux, darwin, windows on amd64 and arm64
maqpna-operator, -attest, -attest-agent, -exec, -egress-relay linux amd64 and arm64
.deb, .rpm, .apk packages (maqpna, maqpna-install) linux
An .spdx.json SBOM per archive —
11 images, each with an SPDX SBOM attestation linux amd64 and arm64

Builds are reproducible: CGO_ENABLED=0, -trimpath, version and commit from -ldflags, file times pinned to the commit time.

Troubleshooting#

Symptom Cause Fix
verify chart or verify image: DENIED: requested access to the resource is denied The GHCR packages are not public yet, or you are not logged in cosign login ghcr.io (or docker login ghcr.io) with a token that can read the packages.
cosign: command not found cosign is not installed Install cosign 2.x or later.
Signature fails with a certificate identity mismatch You passed the image signer for a binary, or the other way round Binaries: the signed-release workflow. Images and chart: the release workflow release.yml. maqpna verify ... -h prints both.
macOS refuses to run the binary Quarantine attribute on a downloaded file After verifying it: xattr -d com.apple.quarantine ./maqpna.

Next steps#