maqpna airgap verify
Verify an air-gap bundle's checksums, signature and images
Synopsis#
maqpna airgap verify DIR [--require-signature] [--key cosign.pub | --certificate-identity[-regexp] I --certificate-oidc-issuer U] [--trusted-root F]Description#
From the help of maqpna airgap:
bundle runs hack/airgap-bundle.sh from a MAQPNA source checkout (--repo, default the current directory). verify exits 3 when a checksum, the signature (with --require-signature) or one of the 11 images fails. push copies every image of images.txt to REG with skopeo, crane or docker; then install with the bundle's hack/airgap-install.sh (SKIP_PUSH=1) or maqpna install.
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--certificate-identity | string | keyless SHA256SUMS.cosign.bundle: exact signer identity | none |
--certificate-identity-regexp | string | keyless: signer identity regexp (default: the MAQPNA release workflows) | none |
--certificate-oidc-issuer | string | keyless: OIDC issuer (default https://token.actions.githubusercontent.com) | none |
--key | string | cosign public key for SHA256SUMS.sig (default DIR/cosign.pub) | none |
--no-image-check | switch | do not require all 11 MAQPNA images in images.txt | none |
--require-signature | switch | fail when the signature is missing or cannot be verified | none |
--trusted-root | string | keyless: Sigstore trusted_root.json for offline verification | none |
The global flags (--context, -o, --no-color, ...) work with every command.
Examples#
maqpna airgap verify bundle/ --require-signature --key cosign.pubWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |
Related commands#
Terminal demo#
This command downloads signatures, images or charts from the network, so the recording shows its help.