maqpna airgap bundle
Build an air-gap install bundle from a source checkout
Synopsis#
maqpna airgap bundle [--repo DIR] [--tag T] [--registry R] [--out DIR] [--key REF | --keyless] [--pull]Description#
From the help of maqpna airgap:
bundle runs hack/airgap-bundle.sh from a MAQPNA source checkout (--repo, default the current directory). verify exits 3 when a checksum, the signature (with --require-signature) or one of the 11 images fails. push copies every image of images.txt to REG with skopeo, crane or docker; then install with the bundle's hack/airgap-install.sh (SKIP_PUSH=1) or maqpna install.
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--agent-sandbox-version | string | upstream agent-sandbox release (env AGENT_SANDBOX_VERSION) | none |
--key | string | cosign key reference for a key-based signature: SHA256SUMS.sig with cosign 2, SHA256SUMS.key.bundle with cosign 3 (env COSIGN_KEY) | none |
--keyless | switch | sign SHA256SUMS keyless (SHA256SUMS.cosign.bundle) | none |
--out | string | output directory (env OUT_DIR; default dist) | none |
--pull | switch | docker pull every image first | none |
--registry | string | source registry of the MAQPNA images (env REGISTRY; default <release-registry>) | none |
--repo | string | MAQPNA source checkout (default: the current directory or a parent) | none |
--tag | string | image tag to bundle (env TAG; default: this CLI's version) | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna airgap bundle --tag v1.4.0 --out bundle/What happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |
Related commands#
Terminal demo#
This command downloads signatures, images or charts from the network, so the recording shows its help.